The HTML Forms – Simple WordPress Forms Plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.0 due to insufficient sanitization of fabricated file upload field metadata before displaying it in the WordPress admin dashboard. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute whenever an administrator accesses the form submissions page.
Metrics
Affected Vendors & Products
References
History
Wed, 17 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 17 Dec 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linksoftware
Linksoftware html Forms Wordpress Wordpress wordpress |
|
| Vendors & Products |
Linksoftware
Linksoftware html Forms Wordpress Wordpress wordpress |
Wed, 17 Dec 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The HTML Forms – Simple WordPress Forms Plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in all versions up to and including 1.6.0 due to insufficient sanitization of fabricated file upload field metadata before displaying it in the WordPress admin dashboard. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute whenever an administrator accesses the form submissions page. | |
| Title | HTML Forms – Simple WordPress Forms Plugin <= 1.6.0 - Unauthenticated Stored Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-12-17T19:29:33.125Z
Reserved: 2025-12-01T21:05:53.563Z
Link: CVE-2025-13861
Updated: 2025-12-17T19:29:23.316Z
Status : Awaiting Analysis
Published: 2025-12-17T05:16:10.977
Modified: 2025-12-18T15:08:06.237
Link: CVE-2025-13861
No data.
OpenCVE Enrichment
Updated: 2025-12-17T14:28:43Z