PT-2026-102708 · WordPress · Balbooa Forms

·

CVE-2026-102425

·

Published

2026-09-29

·

Updated

2026-10-01

CVSS v4.0

9.5

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Balbooa Forms versions prior to 2.4.3.4
Description An unauthenticated remote code execution (RCE) issue exists in the com baforms component. The software allows administrators to define PHP code that executes after a public form submission, which supports the use of form-field shortcodes. The component fails to properly sanitize these shortcodes before passing them to the eval() function, replacing them with raw values submitted by the visitor. This allows an attacker to execute arbitrary code if a public form utilizes the optional PHP-after-submission action and interpolates an attacker-controlled field shortcode within a double-quoted PHP string.
Recommendations Update to version 2.4.3.4 or later.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102425

Affected Products

Balbooa Forms