PT-2026-78353 · WordPress · Balbooa Forms

·

CVE-2026-67364

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Balbooa Forms versions prior to 2.4.3.2
Description An unauthenticated attacker can perform PHP code injection due to the use of the eval() function in the optional custom-PHP post-submission handler. The [URL parameter = X] shortcode is replaced with the raw, unescaped value of a query parameter, allowing arbitrary PHP code to execute on the server. Although a CSRF (Cross-Site Request Forgery) token is required to access the endpoint, it is disclosed anonymously through a separate task. This issue is exploitable if the form has a custom-PHP handler configured that references the shortcode and does not use reCAPTCHA on the submit button.
Recommendations Update to version 2.4.3.2 or later. As a temporary mitigation, disable the custom-PHP post-submission handler or implement reCAPTCHA on the submit button.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67364

Affected Products

Balbooa Forms