Junglewise Threat Intelligence

CVE-2026-9253: Loopus WP Cost Estimation & Payment Forms Builder Stored XSS

CVE-2026-9253 · Severity: high · CVSS 7.2 · Published 2026-07-09

Executive brief

The WP Cost Estimation & Payment Forms Builder plugin for WordPress, used to create service quotes and payment forms, contains a security flaw that allows attackers to inject malicious scripts into the website. Because this vulnerability can be exploited by unauthenticated users, an attacker could potentially steal customer session data or redirect visitors to malicious websites. This impacts the integrity of the website and the security of its users' data.

Technical details

The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'customerInfos' parameter. This vulnerability allows unauthenticated remote attackers to inject arbitrary web scripts into the database. These scripts are then executed in the browser of any user (including administrators) who visits the affected page. The flaw is present in all versions up to and including 10.5.97. Attackers can leverage this to perform actions on behalf of other users or exfiltrate sensitive information such as session cookies.

Affected products

  • Loopus Tech WP Cost Estimation & Payment Forms Builder (E&P Forms) up to, and including, 10.5.97

Timeline

  • 2026-07-09: disclosed
  • 2026-07-09: advisory

References