
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2707 is a Stored Cross-Site Scripting (XSS) vulnerability in the weForms plugin for WordPress, affecting all versions up to and including 1.6.27. The flaw allows authenticated attackers with Subscriber-level access or above to inject malicious scripts into form entry hidden field values via the REST API, which then execute when an administrator views the form entries page. The vulnerability was disclosed on March 11, 2026, with the CVE record submitted by Wordfence. It carries a CVSS v3.1 base score of 6.4 (Medium), assigned by Wordfence (Wordfence, NVD).
The root cause (CWE-79) is inconsistent input sanitization between the plugin's frontend AJAX handler and its REST API endpoint. When form entries are submitted via the REST API (/wp-json/weforms/v1/forms/{id}/entries/), the prepare_entry() method in class-abstract-fields.php receives a WP_REST_Request object as $args instead of $_POST data, causing the weforms_clean() sanitization fallback to be bypassed — the base field handler only applies trim() to the submitted value. The unsanitized payload is then stored and later rendered in the admin entries page using a Vue.js v-html directive without HTML escaping, enabling stored XSS execution (Wordfence, GitHub PR, WordPress Trac).
Successful exploitation allows an authenticated attacker with minimal privileges (Subscriber-level) to store malicious JavaScript that executes in the browser of any administrator who views the form entries page. This can lead to session hijacking, credential theft, unauthorized administrative actions (such as creating rogue admin accounts or installing malicious plugins), and potential full site compromise. The changed scope (S:C in CVSS) reflects that the impact extends beyond the attacker's own session to affect administrator-level users (Wordfence, NVD).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-2707 as of the available data. The EPSS score is approximately 0.036%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only Subscriber-level authentication, which lowers the barrier for abuse on sites with open user registration (Wordfence, Feedly).
curl -s -u 'SUBSCRIBER_USER:APP_PASSWORD' "https://yoursite.com/wp-json/wp/v2/pages/PAGE_ID" | grep -o 'value="[a-f0-9]*"' | head -1curl -s -X POST -u 'SUBSCRIBER_USER:APP_PASSWORD' \
-d '_wpnonce=NONCE&hidden_test="><img src=x onerror=alert(document.cookie)>&form_id=FORM_ID' \
"https://yoursite.com/wp-json/weforms/v1/forms/FORM_ID/entries/"The prepare_entry() method bypasses weforms_clean() and stores the raw payload.
5. Trigger execution: Wait for an administrator to navigate to weForms → (target form) → Entries. The Vue.js v-html directive renders the stored payload as raw HTML, executing the injected script in the admin's browser.
6. Achieve objective: The executed script can exfiltrate session cookies, perform CSRF actions on behalf of the admin (e.g., create a new admin account), or install a backdoor plugin (GitHub PR, Wordfence).
/wp-json/weforms/v1/forms/{id}/entries/ from Subscriber-level accounts, especially containing HTML tags or JavaScript in field values (e.g., <script>, <img src=x onerror=, javascript:).%3Cscript%3E, %3Cimg, onerror); repeated requests from the same low-privilege user account.wp_weforms_entries or related metadata tables containing raw HTML or JavaScript in hidden field values rather than plain text.The BoldGrid/weForms development team merged a patch on March 4, 2026 (PR #263), which sanitizes scalar entry values in the prepare_entry() flow and replaces unsafe v-html rendering with Vue's escaped interpolation for entry list and detail views (restricting v-html to textarea fields only). Users should update the weForms plugin to version 1.6.28 or later, which includes this fix. As an interim workaround, site administrators can disable open user registration to prevent untrusted users from obtaining Subscriber-level accounts, or temporarily restrict REST API access to authenticated users only (GitHub PR, WordPress Changeset).
Wordfence reported the vulnerability in their weekly WordPress vulnerability report for the week of March 9–15, 2026, noting it as part of their ongoing threat intelligence coverage. The vulnerability was also tracked by ENISA under EUVD-2026-11099 and referenced across multiple vulnerability aggregation platforms. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database entries (Wordfence Blog, ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."