Executive brief
CRM Perks Forms, a WordPress plugin used to create and manage website forms, is vulnerable to a security flaw that allows attackers to inject malicious scripts. By tricking a user into clicking a specially crafted link, an attacker can execute code in the user's browser, potentially leading to unauthorized actions or the theft of sensitive session information. This could compromise the integrity of the website and the security of its visitors.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the CRM Perks Forms plugin for WordPress (versions <= 1.1.7) due to improper neutralization of user-supplied input during web page generation. The flaw allows an unauthenticated remote attacker to execute arbitrary JavaScript in the context of a victim's browser session. Exploitation requires a victim to interact with a malicious link or form (User Interaction required). The vulnerability is addressed in version 1.1.8.
Affected products
- CRM Perks CRM Perks Forms <= 1.1.7
Timeline
- 2026-05-29: disclosed: Reported by Baikuya
- 2026-07-08: advisory: Patchstack advisory published
- 2026-07-13: advisory: NVD published date
- 2026-07-08: patched: Version 1.1.8 released