PT-2026-102706 · WordPress · Balbooa Forms

·

CVE-2026-101127

·

Published

2026-09-29

·

Updated

2026-10-01

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Balbooa Forms versions prior to 2.4.3.4
Description An unauthenticated stored Cross-Site Scripting (XSS) issue exists in the public form upload endpoint. While the endpoint validates file extensions and MIME types, it stores the original multipart filename provided by the user verbatim in the # baforms submissions attachments.name field. A subsequent anonymous form submission can associate this temporary attachment with a new submission. When an administrator views the submission, the component's JavaScript retrieves the stored attachment record and concatenates the file.name variable directly into an HTML string, which is then assigned to innerHTML. XSS is a technique where malicious scripts are injected into trusted websites.
Recommendations Update Balbooa Forms to version 2.4.3.4 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101127

Affected Products

Balbooa Forms