Executive brief
ARforms is a popular WordPress plugin used to create and manage forms on websites. A security flaw allows attackers to inject malicious scripts into the 'password' field of these forms. When a site administrator or another user views the submitted data, the script executes in their browser, potentially leading to unauthorized access, data theft, or website defacement.
Technical details
The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on 'password' field values within the arrecordhelper.php component. An unauthenticated remote attacker can submit a form containing malicious JavaScript in the password field. This script is stored in the database and executed in the context of any user (typically an administrator) who views the form entry in the WordPress dashboard. This can lead to session hijacking or administrative account takeover. The vulnerability affects all versions up to and including 7.2.1.
Affected products
- Repute InfoSystems ARforms up to, and including, 7.2.1
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory