Executive brief
Form Vibes is a WordPress plugin used to manage and store submissions from various contact form plugins. A security vulnerability in versions 1.5.2 and earlier allows unauthenticated attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could redirect users to malicious sites, steal session information, or deface the website.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Form Vibes – Database Manager for Forms plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The vulnerability can be exploited by an unauthenticated remote attacker. Successful exploitation requires a victim with higher privileges (such as an administrator) to perform an action, such as clicking a malicious link. Once executed, the attacker's script runs within the context of the victim's browser session, potentially allowing for session hijacking or unauthorized administrative actions. The issue is resolved in version 1.5.3.
Affected products
- WPVibes Form Vibes – Database Manager for Forms <= 1.5.2
Timeline
- 2026-04-17: other: Vulnerability reported by researcher hhhai
- 2026-07-16: advisory: Patchstack advisory published
- 2026-07-23: disclosed: CVE published to NVD dataset
- 2026-07-23: patched: Version 1.5.3 released to address the vulnerability