PT-2025-51810 · WordPress · Simple Wordpress Forms Plugin+1
Itthidej Aramsri
·
Published
2025-12-17
·
Updated
2025-12-17
·
CVE-2025-13861
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
HTML Forms – Simple WordPress Forms Plugin for WordPress versions prior to 1.6.1
Description
The software is susceptible to unauthenticated stored cross-site scripting. Insufficient sanitization of fabricated file upload field metadata before display in the WordPress admin dashboard allows unauthenticated attackers to inject arbitrary web scripts. These scripts execute when an administrator accesses the form submissions page.
Recommendations
Update to version 1.6.1 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Html Forms
Simple Wordpress Forms Plugin