PT-2026-54465 · WordPress · Wpforms

·

CVE-2026-12127

·

Published

2026-07-01

·

Updated

2026-07-01

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More versions prior to 1.10.3
Description An issue exists involving Improper Neutralization of CRLF Sequences (CRLF Injection), where Carriage Return (CR) and Line Feed (LF) characters are not properly handled. This occurs because the get reply to address() function processes the Reply-To display name using the 'notification' context instead of 'notification-reply-to', bypassing email-address validation. Additionally, the wpforms sanitize textarea field() function preserves CR/LF characters that are not stripped before being added to the raw Reply-To: mail header string. Unauthenticated attackers can exploit this by injecting arbitrary email headers, such as Bcc:, into outgoing notification emails to silently blind-copy messages to an attacker-controlled address. This exploitation is possible if a form notification is configured to use a Paragraph Text (textarea) field as the Reply-To display name via a Smart Tag.
Recommendations Update to a version newer than 1.10.2. As a temporary mitigation, avoid configuring form notifications to use a Paragraph Text (textarea) field as the Reply-To display name via a Smart Tag.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12127

Affected Products

Wpforms