What is CVE-2026-7623?
This CVE identifies a Stored Cross-Site Scripting (XSS) vulnerability in the SureForms plugin for WordPress via the 'headingWrapper' parameter. Affecting all versions up to 2.8.1, it allows attackers to inject malicious scripts due to insufficient input sanitization and output escaping. Users should update the plugin immediately and apply proper input validation.
Azərbaycanca: Bu CVE WordPress üçün SureForms plaginində aşkar edilmiş Stored Cross-Site Scripting (XSS) zəifliyidir. 'headingWrapper' parametri üzərindən hücum edənlər zərərli skriptlər yerləşdirə bilər və bu, 2.8.1 daxil olmaqla bütün versiyalara təsir edir. İstifadəçilər dərhal plagini ən son versiyaya yeniləməli və daxil olan məlumatların sanitizasiyasını artırmalıdır.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the SureForms plugin are affected by CVE-2026-7623?
This vulnerability affects all versions of the SureForms plugin up to and including 2.8.1.
Which parameter serves as the attack vector for CVE-2026-7623?
Attackers exploit this Stored XSS vulnerability via the 'headingWrapper' parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.