Sceawere
Vulnerability Detail
CVE-2026-97065UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in Happyforms
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- Happyforms
- Product
- Happyforms
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in Happyforms <= 1.26.15 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-30T13:17:33.950Z",
"pubdate": "2026-09-30T13:17:33.950Z",
"executiveSummary": "The Happyforms plugin for WordPress, specifically versions 1.26.15 and below, contains a critical vulnerability categorized as Unauthenticated Stored Cross-Site Scripting (XSS).\nThis flaw allows remote, unauthenticated attackers to inject malicious JavaScript into web pages rendered by the application.\nThe vulnerability exists because the plugin fails to properly sanitize or validate user-supplied input before reflecting it within the administrative or public-facing interface.\nSuccessful exploitation poses a significant security risk, as it enables the execution of arbitrary code within the context of a victim's browser session.\nAttackers can leverage this to steal sensitive session cookies, perform unauthorized actions on behalf of authenticated administrators, redirect users to malicious domains, or deface the website.\nSince the attack does not require authentication, the surface area for this vulnerability is broad, exposing any site utilizing an affected version of Happyforms to immediate compromise.\nGiven the severity and the potential for full administrative account takeover through session hijacking, immediate remediation is strongly advised.",
"technicalDetails": "The vulnerability is a classic case of improper input sanitization and output encoding within the Happyforms plugin ecosystem. The core issue resides in the plugin's handling of user-submitted form data, which is subsequently processed and rendered in a way that allows for the interpretation of HTML tags and script elements by the browser.\nIn versions 1.26.15 and earlier, the application fails to adequately sanitize input parameters that are later displayed within the WordPress dashboard or, in certain configurations, on the front-end. When a user submits a form, the malicious payload is stored in the database. When a privileged user, such as an administrator, views the submission data, the application fails to implement context-aware output encoding (such as escaping characters like <, >, \", and ').\nThe attack flow proceeds as follows: First, an unauthenticated attacker identifies a public-facing form generated by Happyforms. Second, the attacker crafts a malicious payload, typically a <script> tag or an event handler such as onload or onerror, injecting it into an input field. Third, the application receives this input and writes it directly to the database without appropriate sanitization. Fourth, the malicious script resides in the database until a high-privileged user interacts with the plugin's submission management interface. Finally, when the administrator navigates to the submissions panel, the browser renders the injected payload. Because the victim is viewing the data in a logged-in state, the script executes with the administrator's privileges.\nThis exploitation vector bypasses standard authentication controls because the payload is triggered by the administrator's interaction with the data, rather than the attacker's own credentials. Post-exploitation impact is severe; the executed script can perform any action the administrator can perform, including creating new admin accounts, modifying site settings, or installing malicious plugins. Furthermore, if the input is reflected on the front-end, it could lead to broader site-wide attacks against non-privileged visitors. The vulnerability confirms that the application does not adhere to secure coding practices regarding input validation and output encoding, effectively turning the plugin's intended functionality into a delivery mechanism for malicious client-side code."
}