CVE-2026-18406
moderateUnauthenticated Stored XSS in SureForms WordPress Contact Form Plugin
CVE-2026-18406 is a stored cross-site scripting vulnerability in the SureForms contact form plugin for WordPress, caused by insufficient input sanitization and output escaping of text field submissions containing entity-encoded payloads. An unauthenticated attacker can submit a crafted payload through a SureForms form's text field; the payload is stored on the site and executes as arbitrary web script whenever any user accesses an affected page. Successful exploitation allows the attacker to run JavaScript in the browsers of site visitors and administrators, potentially enabling session theft, redirects, or privileged actions. Any WordPress site running SureForms version 2.12.2 or earlier with a published form using a text field is affected. No public proof-of-concept or in-the-wild exploitation is known, and EPSS currently estimates only a 0.3% probability of exploitation within 30 days.
What to do: Update the SureForms plugin to the latest available release (any version newer than 2.12.2) as soon as a patched version is published. Until updated, review existing stored form entries and pages containing SureForms forms for unexpected script tags or encoded payloads, and temporarily restrict or monitor unauthenticated form submissions. No exploitation has been reported, so patching promptly should preempt any in-the-wild attacks.
| SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz (WordPress plugin) | All versions up to and including 2.12.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded Payload in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.