Description
The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts.
Published: 2026-09-28
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Arbitrary Shortcode Execution and Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

WPForms Lite WordPress plugin versions 1.5.0.1 through 2.0.2 contains a flaw where submitted form field values are written back into the page without removing shortcode delimiters. This omission lets any visitor, without authentication, insert and execute arbitrary shortcodes that are registered on the site. Because shortcodes can invoke plugin and core WordPress functions, an attacker could run code that reads or manipulates file attachments to non-public posts, exposing sensitive data. The weakness is a code injection type flaw with potential for information disclosure, as reflected by CWE‑94 and CWE‑200.

Affected Systems

The affected product is the WPForms Lite WordPress plugin. Vulnerable releases are any version from 1.5.0.1 up to and including 2.0.2. The vendor is WPForms, but the CNA lists it as Unknown:WPForms.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. EPSS is unavailable, and the vulnerability is not listed in CISA KEV. Because the flaw allows unauthenticated users to craft a form submission, the likely attack vector is a simple HTTP POST request to the vulnerable form. No special privileges or local access are required, and exploitation does not appear to be dependent on other configuration weaknesses, making the risk significant for sites that keep the plugin at these versions.

Generated by OpenCVE AI on September 28, 2026 at 07:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WPForms Lite to a version newer than 2.0.2 or to the latest release available from the WordPress repository to eliminate the vulnerability.
  • If an immediate upgrade is not feasible, disable or strip shortcodes from submitted form values by configuring the plugin’s shortcode handling settings or by deploying a security plugin that sanitizes input to remove any shortcode delimiters.
  • Apply access controls to limit form submissions to authenticated users only, or otherwise restrict untrusted input to reduce the surface for arbitrary shortcode execution.

Generated by OpenCVE AI on September 28, 2026 at 07:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-94

Mon, 28 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts.
Title WPForms Lite 1.5.0.1 - 2.0.2 - Unauthenticated Arbitrary Shortcode Execution via Form Field Repopulation
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-28T06:19:19.942Z

Reserved: 2026-09-02T08:41:22.689Z

Link: CVE-2026-84744

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T07:17:20.827

Modified: 2026-09-28T07:17:20.827

Link: CVE-2026-84744

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T07:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')