Junglewise Threat Intelligence

CVE-2026-84744: WPForms Lite arbitrary shortcode execution via form field repopulation

CVE-2026-84744 · Severity: medium · CVSS 6.5 · Published 2026-09-28

Vendors: WPForms.

Executive brief

WPForms Lite is a WordPress plugin for building forms on websites. The plugin fails to sanitize user input before displaying submitted form values back to the page, allowing attackers to inject and execute arbitrary shortcodes. This enables reading sensitive data from non-public posts or executing unintended functionality registered on the site.

Technical details

The vulnerability is a shortcode injection flaw in form field repopulation logic. Unauthenticated attackers can submit forms with malicious shortcode delimiters in field values; the plugin renders these values back into the form without removing the delimiters, causing arbitrary registered shortcodes to execute with the privileges of the WordPress site. No authentication is required and the attack vector is network-based via form submission.

Affected products

  • WPForms WPForms Lite 1.5.0.1 to 2.0.2

Timeline

  • 2026-09-24: disclosed
  • 2026-09-28: advisory
  • 2026-09-28: patched: Fixed in version 2.0.2.1

References

Related threats