Sceawere

Vulnerability Detail

CVE-2026-84744UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WPForms Lite Shortcode Injection Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
2h ago
Vendor
Unknown
Product
WPForms
Attack Type
CWE-94 Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-28T07:17:20.827Z",
  "pubdate": "2026-09-28T07:17:20.827Z",
  "executiveSummary": "The WPForms Lite WordPress plugin, within versions 1.5.0.1 through 2.0.2, contains a critical security flaw involving improper input sanitization. The vulnerability is classified as an improper neutralization of input during web page generation, leading to an unauthorized shortcode execution primitive.\nUnauthenticated attackers can leverage this defect to inject arbitrary WordPress shortcodes into form field values. When these values are rendered back to the user or an administrator, the site executes the injected shortcodes.\nThe primary impact involves unauthorized information disclosure. By injecting specifically crafted shortcodes, an attacker can bypass security boundaries to access, read, or disclose sensitive details of attachments associated with non-public or private posts that would otherwise be restricted from public view.\nThis vulnerability represents a significant risk to site integrity and data confidentiality, as it allows for the manipulation of the application's rendering logic without requiring prior authentication or elevated privileges.",
  "technicalDetails": "The root cause of this vulnerability lies in the failure of the WPForms Lite plugin to implement adequate sanitization or removal of shortcode delimiters (e.g., '[' and ']') when processing submitted form field data. This lack of filtering allows malicious payloads to persist in the database and be rendered within the application's front-end context.\nThe attack flow commences when an unauthenticated user submits a form generated by the affected plugin. The attacker embeds a malicious shortcode payload within one of the input fields. Because the plugin does not strip or neutralize these delimiters, the malicious string is stored in the application backend as valid user input.\nWhen the form data is subsequently processed and rendered—such as in an administrative view, an email notification, or a front-end preview—the WordPress Shortcode API parses the submitted input. The application treats the injected string as a legitimate internal shortcode, triggering its execution.\nExploitation allows for the unauthorized retrieval of data. By crafting payloads that utilize existing site shortcodes—specifically those capable of querying database content or attachments—the attacker can force the system to return information that should be restricted based on current user session permissions or visibility settings.\nThis vulnerability is particularly impactful regarding attachments linked to non-public posts. Since the shortcode executes within the context of the WordPress installation, it can bypass front-end access controls, effectively allowing the attacker to retrieve file metadata or content that the application logic intended to keep private.\nThe vulnerability is present in versions 1.5.0.1 through 2.0.2. No authentication is required for exploitation, and the attack can be launched from any network location where the form is accessible. The payload is executed on the server side when the shortcode is parsed by the WordPress rendering engine during the form submission review process."
}
CVE-2026-84744: WPForms Lite Shortcode Injection Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere