Junglewise Threat Intelligence

CVE-2026-15782: WPForms Stored XSS in OptinMonster Integration

CVE-2026-15782 · Severity: medium · CVSS 4.9 · Published 2026-07-21

Technologies: WPForms. Vendors: WPForms.

Executive brief

WPForms is a popular WordPress plugin used to create contact and payment forms. A security flaw allows users with contributor-level access to inject malicious scripts into website pages. If exploited, these scripts could run in the browsers of other visitors, potentially leading to unauthorized actions or data theft, though the attack requires specific integration with the OptinMonster plugin to be active.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in WPForms due to insufficient input sanitization and output escaping of the 'data-sitekey' attribute within the OptinMonster integration. Authenticated attackers with contributor-level permissions or higher can inject malicious JavaScript into post content. The vulnerability is triggered when the OptinMonster plugin is installed and configured with an active inline campaign that emits the 'om.Campaign.load' event. When this event fires, the WPForms handler processes the malicious attribute, leading to script execution in the context of the victim's browser. The issue is addressed in versions following 2.0.0.1.

Affected products

  • smub WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More up to, and including, 2.0.0.1

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats