Junglewise Threat Intelligence

CVE-2026-65442: Subtle Web Inc FormCraft SSRF in WordPress plugin

CVE-2026-65442 · Severity: high · CVSS 7.2 · Published 2026-07-27

Executive brief

FormCraft, a popular WordPress plugin used for building custom forms, contains a security flaw that allows unauthorized individuals to force the web server to make requests to other websites or internal systems. An attacker could exploit this to scan internal networks, access sensitive data from other services running on the same server, or bypass security controls. This vulnerability can be exploited remotely without needing a username or password.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the FormCraft plugin for WordPress (versions <= 3.9.15). The flaw allows an unauthenticated remote attacker to submit crafted requests that the server will then execute, potentially targeting internal network resources or external domains. This is classified as CWE-918 and stems from insufficient validation of user-supplied URLs. Successful exploitation can lead to information disclosure of internal services or unauthorized interaction with third-party APIs. The issue is resolved in version 3.9.16.

Affected products

  • Subtle Web Inc FormCraft <= 3.9.15

Timeline

  • 2026-07-03: disclosed: Reported by researcher luc
  • 2026-07-27: advisory: Patchstack published advisory and CVE-2026-65442 was released
  • 2026-07-27: patched: Version 3.9.16 released to address the vulnerability

References