Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through <= 2.15.3.
Published: 2026-07-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stored cross‑site scripting flaw arises from the FormyChat plugin’s failure to neutralize user input before rendering it within a web page. A malicious user can submit script code through the plugin’s form container, and that code will be persisted and subsequently executed in the browsers of any visitor who loads can enable data theft, page defacement, or phishing attacks.

Affected Systems

WordPress sites that have installed the WPPOOL FormyChat plugin in any version up to and including 2.15.3. Any installation of the plugin in these releases is vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a high‑severity vulnerability. An EPSS score of less than 1% suggests that exploit attempts are rare, and the vulnerability is not listed in the CISA KEV catalog, so no widespread incidents are currently reported. Exploitation requires the attacker to deposit a malicious payload via the plugin’s input interface; once stored, the payload will be delivered to all users who view the affected page. Because the flaw is client‑side, an attacker can carry out the attack remotely through the form fields, impacting all site visitors.

Generated by OpenCVE AI on July 31, 2026 at 12:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify the installed version of FormyChat; if the site is running version 2.15.3 or older, obtain an update from WPPOOL or the plugin repository.
  • If a patch is not available, permanently remove or deactivate the FormyChat plugin to eliminate the vulnerable input surface.
  • Configure a web application firewall or set a content security policy that blocks or sanitizes script tags injected into form fields.
  • Continuously monitor the site for unexpected script injections and review server logs for signs of attempted exploitation.

Generated by OpenCVE AI on July 31, 2026 at 12:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wppool
Wppool formychat
Vendors & Products Wordpress
Wordpress wordpress
Wppool
Wppool formychat

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through <= 2.15.3.
Title WordPress FormyChat plugin <= 2.15.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
Wppool Formychat
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:39:24.727Z

Reserved: 2026-06-24T12:45:54.515Z

Link: CVE-2026-57379

cve-icon Vulnrichment

Updated: 2026-07-13T13:54:51.313Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')