PT-2026-24579 · Boldgrid · Weforms – Easy Drag & Drop Contact Form Builder For Wordpress

Muhammad Sharief

·

Published

2026-03-11

·

Updated

2026-03-15

·

CVE-2026-2707

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions weForms versions up to and including 1.6.27
Description The weForms plugin for WordPress is susceptible to Stored Cross-Site Scripting through the REST API entry submission endpoint. This occurs because of inconsistent input sanitization between the frontend AJAX handler and the REST API endpoint. When entries are submitted via the REST API, the prepare entry() method in class-abstract-fields.php receives the WP REST Request object as $args, bypassing the sanitization process applied to $ POST data for frontend submissions. The base field handler only applies trim() to the value. This allows authenticated attackers with Subscriber-level access or higher to inject malicious web scripts into form entry hidden field values via the REST API endpoint: /wp-json/weforms/v1/forms/{id}/entries/. These scripts execute when an administrator views the form entries page, where data is rendered using a Vue.js v-html directive without proper escaping.
Recommendations Update weForms to a version later than 1.6.27.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-2707

Affected Products

Weforms – Easy Drag & Drop Contact Form Builder For Wordpress