What is CVE-2026-12421?
CVE-2026-12421: Stored Cross-Site Scripting (XSS) vulnerability in the ARforms plugin for WordPress. Affects all versions up to and including 7.2.1, allowing unauthenticated attackers to inject arbitrary web scripts via the 'password' field due to insufficient input sanitization.
Azərbaycanca: CVE-2026-12421: WordPress üçün ARforms plaginində aşkar edilmiş Stored Cross-Site Scripting (XSS) zəifliyidir. 7.2.1 daxil olmaqla bütün versiyalara təsir edir və 'password' sahəsi vasitəsilə autentifikasiya olunmamış hücumçulara zərərli skript yerləşdirməyə imkan verir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the ARforms plugin are affected by CVE-2026-12421?
This vulnerability affects all versions of the ARforms plugin up to and including 7.2.1.
Is authentication required for an attacker to exploit CVE-2026-12421?
No, unauthenticated attackers can exploit this vulnerability via the 'password' field.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.