Impact
The WPForms AI Form Builder for WordPress plugin is vulnerable to a stored cross‑site scripting flaw caused by insufficient input sanitization and output escaping. An authenticated user with contributor‑level access or higher can inject arbitrary JavaScript into post content through the OptinMonster integration’s data‑sitekey attribute. When a user views the affected page, the malicious script runs in their browser, potentially defacing the site, stealing cookies, or hijacking user sessions. The vulnerability is a pure input‑validation issue and does not allow arbitrary code execution beyond the victim’s browser context.
Affected Systems
WordPress sites running WPForms versions up to and including 2.0.0.1 are affected. The flaw exists only when the OptinMonster plugin is installed and an active inline campaign that outputs #om‑{id} markup is present, as the WPForms handler listens for the ‘om.Campaign.load’ event. All other WordPress core or theme versions are unaffected directly.
Risk and Exploitability
The CVSS score of 4.9 reflects moderate severity. EPSS indicates a very low – but nonzero – probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated and possess contributor‑level or higher privileges, and the presence of an active OptinMonster inline campaign is required. No widespread public exploitation has been reported, yet the risk remains for sites that have not applied the fix.
OpenCVE Enrichment