CVE-2026-2707: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-2707 is a Stored Cross-Site Scripting (XSS) vulnerability in the weForms plugin for WordPress, affecting all versions up to and including 1.6.27. The flaw allows authenticated attackers with Subscriber-level access or above to inject malicious scripts into form entry hidden field values via the REST API, which then execute when an administrator views the form entries page. The vulnerability was disclosed on March 11, 2026, with the CVE record submitted by Wordfence. It carries a CVSS v3.1 base score of 6.4 (Medium), assigned by Wordfence (Wordfence, NVD).

Technical details

The root cause (CWE-79) is inconsistent input sanitization between the plugin's frontend AJAX handler and its REST API endpoint. When form entries are submitted via the REST API (/wp-json/weforms/v1/forms/{id}/entries/), the prepare_entry() method in class-abstract-fields.php receives a WP_REST_Request object as $args instead of $_POST data, causing the weforms_clean() sanitization fallback to be bypassed — the base field handler only applies trim() to the submitted value. The unsanitized payload is then stored and later rendered in the admin entries page using a Vue.js v-html directive without HTML escaping, enabling stored XSS execution (Wordfence, GitHub PR, WordPress Trac).

Impact

Successful exploitation allows an authenticated attacker with minimal privileges (Subscriber-level) to store malicious JavaScript that executes in the browser of any administrator who views the form entries page. This can lead to session hijacking, credential theft, unauthorized administrative actions (such as creating rogue admin accounts or installing malicious plugins), and potential full site compromise. The changed scope (S:C in CVSS) reflects that the impact extends beyond the attacker's own session to affect administrator-level users (Wordfence, NVD).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-2707 as of the available data. The EPSS score is approximately 0.036%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only Subscriber-level authentication, which lowers the barrier for abuse on sites with open user registration (Wordfence, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the weForms plugin (version ≤ 1.6.27) with open user registration or an existing low-privilege account. Tools like WPScan can enumerate installed plugins and versions.
  2. Obtain credentials and nonce: Authenticate as a Subscriber-level user with an Application Password (configured via WP Admin → Users → Edit User → Application Passwords). Retrieve a valid WPUF nonce by querying a page containing the weForms shortcode: curl -s -u 'SUBSCRIBER_USER:APP_PASSWORD' "https://yoursite.com/wp-json/wp/v2/pages/PAGE_ID" | grep -o 'value="[a-f0-9]*"' | head -1
  3. Identify target form: Note the form ID containing a Hidden Field and its meta key name from the weForms admin panel or page source.
  4. Submit XSS payload via REST API: Send a crafted POST request to the REST API entry endpoint with a malicious payload in the hidden field parameter:
curl -s -X POST -u 'SUBSCRIBER_USER:APP_PASSWORD' \
  -d '_wpnonce=NONCE&hidden_test="><img src=x onerror=alert(document.cookie)>&form_id=FORM_ID' \
  "https://yoursite.com/wp-json/weforms/v1/forms/FORM_ID/entries/"

The prepare_entry() method bypasses weforms_clean() and stores the raw payload. 5. Trigger execution: Wait for an administrator to navigate to weForms → (target form) → Entries. The Vue.js v-html directive renders the stored payload as raw HTML, executing the injected script in the admin's browser. 6. Achieve objective: The executed script can exfiltrate session cookies, perform CSRF actions on behalf of the admin (e.g., create a new admin account), or install a backdoor plugin (GitHub PR, Wordfence).

Indicators of compromise

  • Network: Unusual authenticated POST requests to /wp-json/weforms/v1/forms/{id}/entries/ from Subscriber-level accounts, especially containing HTML tags or JavaScript in field values (e.g., <script>, <img src=x onerror=, javascript:).
  • Logs: WordPress access logs showing REST API POST requests to the weForms entries endpoint with URL-encoded HTML payloads (%3Cscript%3E, %3Cimg, onerror); repeated requests from the same low-privilege user account.
  • Database: Entries in the wp_weforms_entries or related metadata tables containing raw HTML or JavaScript in hidden field values rather than plain text.
  • Admin Behavior: Unexpected JavaScript execution (alert dialogs, redirects, or network requests to external domains) when an administrator views the weForms entries page; new administrator accounts created without authorization shortly after an admin views entries.

Mitigation and workarounds

The BoldGrid/weForms development team merged a patch on March 4, 2026 (PR #263), which sanitizes scalar entry values in the prepare_entry() flow and replaces unsafe v-html rendering with Vue's escaped interpolation for entry list and detail views (restricting v-html to textarea fields only). Users should update the weForms plugin to version 1.6.28 or later, which includes this fix. As an interim workaround, site administrators can disable open user registration to prevent untrusted users from obtaining Subscriber-level accounts, or temporarily restrict REST API access to authenticated users only (GitHub PR, WordPress Changeset).

Community reactions

Wordfence reported the vulnerability in their weekly WordPress vulnerability report for the week of March 9–15, 2026, noting it as part of their ongoing threat intelligence coverage. The vulnerability was also tracked by ENISA under EUVD-2026-11099 and referenced across multiple vulnerability aggregation platforms. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability database entries (Wordfence Blog, ENISA EUVD).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management