Description
The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-07-11
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Form Vibes plugin for WordPress does not from Contact Form 7 form fields before storing them in the database. Attackers can embed arbitrary JavaScript that is then executed automatically whenever a page displaying that stored entry is accessed.

Affected Systems

All WordPress sites that have the wpvibes Form V7 & Elementor Form Entries to Database plugin installed and enabled in version 1.5.2 or earlier are affected. Any public Contact Form 7 form that submits data through the plugin’s storage mechanism can be used to inject malicious code, and no user authentication is required to perform the attack.

Risk and Exploitability

With a CVSS score of 7.2 the vulnerability is high severity, yet the EPSS score of less than 1 % indicates a low likelihood of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. Attackers can reach exploitable input points via the public form submission endpoint, making the attack vector web‑based and unauthenticated. If exploited, malicious code persists and runs for every user who views the impacted entry.

Generated by OpenCVE AI on July 29, 2026 at 09:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Form Vibes plugin to the latest version that contains the input validation and output escaping fix.
  • If an update is unavailable, remove the plugin or disable contact form functionality until a patch is released.
  • Apply a web application firewall rule to block script‑containing payloads submitted through the form fields and enforce strict input filtering and output escaping for all form data.

Generated by OpenCVE AI on July 29, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpvibes
Wpvibes form Vibes – Save Contact Form 7 & Elementor Form Entries To Database
Vendors & Products Wordpress
Wordpress wordpress
Wpvibes
Wpvibes form Vibes – Save Contact Form 7 & Elementor Form Entries To Database

Sat, 11 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Form Vibes <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting via Contact Form 7 Form Field
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wpvibes Form Vibes – Save Contact Form 7 & Elementor Form Entries To Database
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-13T16:12:47.968Z

Reserved: 2026-06-25T21:12:54.787Z

Link: CVE-2026-13378

cve-icon Vulnrichment

Updated: 2026-07-13T16:12:44.725Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T09:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')