Impact
The vulnerability in the WPForms plug‑in allows attackers to inject arbitrary email headers through the Reply‑To display name field. The plug‑in incorrectly processes smart tags in the reply‑to field, bypassing validation and preserving CR/LF characters, which enables a CRLF injection that can add headers such as Bcc. This results in an attacker silently receiving copies of notification emails.
Affected Systems
Any WordPress site that runs WPForms version 1.10.2 or older, including all earlier releases of the plug‑in. Exploitation requires that a form contain a Paragraph Text (textarea) field configured as the Reply‑To display name via a smart tag.
Risk and Exploitability
This vulnerability has a CVSS score of 5.3, classifying it as medium severity. The EPSS score is currently unavailable, and it is not listed in the CISA KEV inventory. An attacker can exploit the flaw remotely by submitting data to a publicly accessible form that uses a textarea field as the reply‑to display name; no authentication is required. If the site has not been updated to 1.10.2 and the form is configured accordingly, each notification email will be silently BCC‑ed to an arbitrary address.
OpenCVE Enrichment