Executive brief
The FormCraft plugin for WordPress, which is used to create and manage web forms, contains a security flaw that allows attackers to inject malicious scripts into the website. Because the plugin fails to properly clean data submitted through certain form fields, an unauthenticated attacker can store harmful code that executes in the browser of any user who views the affected page. This could lead to unauthorized actions being performed in a user's session or the theft of sensitive information.
Technical details
The FormCraft plugin for WordPress (up to 3.9.14) is vulnerable to Stored XSS via two primary exploit vectors. First, composite matrix sub-field keys (e.g., field2_0) bypass the server-side sanitization loop and are stored raw via $wpdb->insert(). On the client side, DOMPurify is bypassed because it only validates string types, while matrix values arrive as arrays before being mapped to the DOM. Second, array-typed field values are passed through htmlentities() on submission but are later reversed by html_entity_decode() in formcraft-main.php (lines 2608 and 2122) before rendering. These flaws allow unauthenticated remote attackers to achieve persistent script execution in the context of a user's browser. The issue was addressed in version 3.9.15.
Affected products
- FormCraft FormCraft up to, and including, 3.9.14
Timeline
- 2026-06-02: patched: Version 3.9.15 released to fix XSS vulnerability
- 2026-07-23: disclosed: CVE-2026-7232 published