ZeroHour

CVE-2026-18406

moderate

Unauthenticated Stored XSS in SureForms WordPress Contact Form Plugin

CVSS 3.1
7.2 high
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-18406 is a stored cross-site scripting vulnerability in the SureForms contact form plugin for WordPress, caused by insufficient input sanitization and output escaping of text field submissions containing entity-encoded payloads. An unauthenticated attacker can submit a crafted payload through a SureForms form's text field; the payload is stored on the site and executes as arbitrary web script whenever any user accesses an affected page. Successful exploitation allows the attacker to run JavaScript in the browsers of site visitors and administrators, potentially enabling session theft, redirects, or privileged actions. Any WordPress site running SureForms version 2.12.2 or earlier with a published form using a text field is affected. No public proof-of-concept or in-the-wild exploitation is known, and EPSS currently estimates only a 0.3% probability of exploitation within 30 days.

What to do: Update the SureForms plugin to the latest available release (any version newer than 2.12.2) as soon as a patched version is published. Until updated, review existing stored form entries and pages containing SureForms forms for unexpected script tags or encoded payloads, and temporarily restrict or monitor unauthenticated form submissions. No exploitation has been reported, so patching promptly should preempt any in-the-wild attacks.

Affected
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz (WordPress plugin)All versions up to and including 2.12.2
Estimated exposure
moderate≈10,000–20,000 WordPress sites (plugin's WordPress.org active-install count) — Estimate based on the SureForms plugin's active-install count on the WordPress.org directory; it is a recently released form builder whose adoption is in the low tens of thousands, far behind incumbents like Contact Form 7 or WPForms.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded Payload in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.