PT-2026-99773 · WordPress · Wpforms Lite
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WPForms Lite versions 1.5.0.1 through 2.0.2
Description
The plugin fails to remove shortcode delimiters from submitted field values before they are written back into the rendered form. This allows unauthenticated users to execute arbitrary shortcodes registered on the site, which can be used to read details of attachments belonging to non-public posts.
Recommendations
Update WPForms Lite to a version newer than 2.0.2.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wpforms Lite