What is CVE-2026-7232?
A Stored Cross-Site Scripting (Stored XSS) vulnerability has been discovered in the FormCraft plugin for WordPress. Versions up to and including 3.9.14 lack sufficient input sanitization and output escaping in the '[parameter name]' parameter, allowing unauthenticated attackers to inject arbitrary web scripts. It is recommended to update the plugin to the latest version.
Azərbaycanca: WordPress üçün FormCraft plaginində Saxlanılan Cross-Site Scripting (Stored XSS) zəifliyi aşkar edilib. Plaginin 3.9.14-ə qədər olan versiyaları '[parameter name]' parametrində kifayət qədər input sanitization və output escaping olmaması səbəbindən autentifikasiya olunmamış hücumçulara veb skriptlər inyeksiya etməyə imkan verir. Plaginin son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What security vulnerability is associated with the FormCraft plugin for WordPress?
The FormCraft plugin for WordPress has a stored Cross-Site Scripting (Stored XSS) vulnerability in versions up to and including 3.9.14 due to insufficient input sanitization and output escaping in the '[parameter name]' parameter.
Is authentication required to exploit this FormCraft XSS vulnerability?
No, this vulnerability can be exploited by unauthenticated attackers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.