Description
The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'attacker-chosen key referenced by the smart tag (e.g. "x")' parameter in all versions up to, and including, 2.0.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that a site administrator has previously saved a form whose description embeds a {query_var} Smart Tag inside an iframe srcdoc attribute and has enabled Show Description on a public-facing page.
Published: 2026-10-10
Score: 4.7 Medium
EPSS: n/a
KEV: No
Impact: Reflected Cross‑Site Scripting
Action: Upgrade
AI Analysis

Impact

The vulnerability allows an attacker to inject arbitrary JavaScript into a page that a visitor might open in a browser. The flaw is due to insufficient sanitization of a query string key referenced by the {query_var} smart tag, which is rendered inside an iframe srcdoc attribute. An attacker can exploit this when a form description containing the smart tag is displayed publicly and the user follows a crafted link that supplies a malicious value for the key. The resulting script runs in the context of the site, enabling data theft, cookie theft, or redirection.

Affected Systems

WordPress sites running the WPForms – AI Form Builder for WordPress plugin version 2.0.2.1 or earlier. The plugin is used for creating contact, payment, survey, quiz and other forms. Any site administrator who has saved a form whose description embeds a {query_var} smart tag inside an iframe srcdoc attribute and has enabled the display of the description on a public page is susceptible.

Risk and Exploitability

The CVSS score of 4.7 categorizes the flaw as moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. However, the requirement that the site already displays a vulnerable form means attackers can target sites that expose such forms, using social engineering to lure users to click a malicious link. The impact is limited to the victim’s browser and does not compromise the server directly.

Generated by OpenCVE AI on October 10, 2026 at 09:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WPForms to the latest version (≥ 2.0.2.2) to remove the vulnerable smart tag handling
  • If an upgrade is not possible, delete or edit any forms that include a {query_var} Smart Tag within an iframe srcdoc attribute and disable the “Show Description” option on public pages
  • Apply a content security policy that restricts execution of inline scripts and limits the domains from which scripts can load

Generated by OpenCVE AI on October 10, 2026 at 09:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'attacker-chosen key referenced by the smart tag (e.g. "x")' parameter in all versions up to, and including, 2.0.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. Exploitation requires that a site administrator has previously saved a form whose description embeds a {query_var} Smart Tag inside an iframe srcdoc attribute and has enabled Show Description on a public-facing page.
Title WPForms <= 2.0.2.1 - Reflected Cross-Site Scripting via 'query_var' Smart Tag in iframe srcdoc Attribute
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T07:41:44.285Z

Reserved: 2026-09-28T16:00:15.271Z

Link: CVE-2026-101921

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:03.350

Modified: 2026-10-10T08:17:03.350

Link: CVE-2026-101921

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')