Executive brief
The Formidable Kinetic plugin for WordPress, which provides specialized link and display functionality, contains a security flaw that allows users with basic posting privileges to inject malicious scripts into website pages. These scripts execute automatically in the browser of any visitor who views the affected page. This could lead to unauthorized actions being performed on behalf of site administrators or the theft of sensitive session information.
Technical details
The Formidable Kinetic plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'kinetic_link' shortcode in versions up to, and including, 1.1.01. The vulnerability exists within the FrmKinetic::link() function, where user-supplied shortcode attributes—specifically 'window', 'class', and 'label'—are concatenated directly into the HTML attributes of an anchor tag without adequate sanitization or output escaping. An authenticated attacker with contributor-level permissions or higher can exploit this to inject arbitrary web scripts. These scripts are stored on the server and execute in the context of any user's browser session when they visit the compromised page.
Affected products
- Formidable Kinetic Formidable Kinetic Up to, and including, 1.1.01
Timeline
- 2026-05-27: advisory: Initial disclosure by Wordfence and NVD