PT-2026-6028 · WordPress · Wordpress+1
Supakiad S
·
Published
2026-02-03
·
Updated
2026-02-03
·
CVE-2026-1058
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Form Maker plugin for WordPress versions prior to 1.15.36
Description
The Form Maker plugin for WordPress is susceptible to Stored Cross-Site Scripting through hidden field values. Insufficient output escaping when displaying these values in the admin submissions list allows for the execution of arbitrary web scripts. The plugin utilizes
html entity decode() on user-supplied hidden field values without subsequent escaping before output, converting HTML entity-encoded payloads into executable JavaScript. This enables unauthenticated attackers to inject malicious scripts into the admin submissions view, which will execute when an administrator accesses the submissions list.Recommendations
Update the Form Maker plugin to version 1.15.36 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Form Maker
Wordpress