Impact
The SureForms plugin targeted by CVE‑2026‑18406 has a stored XSS flaw that allows unauthenticated users to inject arbitrary scripts into the form entry database by using an entity‑encoded payload in a text field. Attackers can cause the script to execute whenever any visitor loads a page containing that stored content, leading to session hijacking, defacement, or phishing attacks. The weakness is a typical input validation and output encoding failure listed under CWE‑79.
Affected Systems
Benelisting: The plugin in all WordPress installations that use SureForms or its derivatives – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz – is vulnerable on every version up through 2.12.2. No later version details are provided, so any deployment newer than 2.12.2 is presumed safe but should be verified. Administrators should review the plugin version on their site.
Risk and Exploitability
The assessment assigns a CVSS base score of 7.2, indicating a high impact with unauthenticated attackers. Because the patch is not trivial, an attacker can easily construct a malicious payload via the public form, store it, and wait for other users to trigger it. The EPSS score is not available, but the fact that the flaw requires only a public web form suggests a realistic exploitation probability. The flaw is not listed in CISA's KEV catalog, but the stored nature of the exploit means that any user who views the compromised page is at risk.
OpenCVE Enrichment