PT-2026-54465 · WordPress · Wpforms
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More versions prior to 1.10.3
Description
An issue exists involving Improper Neutralization of CRLF Sequences (CRLF Injection), where Carriage Return (CR) and Line Feed (LF) characters are not properly handled. This occurs because the
get reply to address() function processes the Reply-To display name using the 'notification' context instead of 'notification-reply-to', bypassing email-address validation. Additionally, the wpforms sanitize textarea field() function preserves CR/LF characters that are not stripped before being added to the raw Reply-To: mail header string. Unauthenticated attackers can exploit this by injecting arbitrary email headers, such as Bcc:, into outgoing notification emails to silently blind-copy messages to an attacker-controlled address. This exploitation is possible if a form notification is configured to use a Paragraph Text (textarea) field as the Reply-To display name via a Smart Tag.Recommendations
Update to a version newer than 1.10.2.
As a temporary mitigation, avoid configuring form notifications to use a Paragraph Text (textarea) field as the Reply-To display name via a Smart Tag.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpforms