The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-side script execution, allowing authenticated users with Editor-level access and above to perform Stored Cross-Site Scripting attacks against any visitor of a page rendering the affected form, even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network).
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 15 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Mon, 15 Jun 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-side script execution, allowing authenticated users with Editor-level access and above to perform Stored Cross-Site Scripting attacks against any visitor of a page rendering the affected form, even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network). | |
| Title | Form Builder CP < 1.2.47 - Editor+ Stored XSS via form_structure | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-06-15T06:00:02.522Z
Reserved: 2026-05-22T12:25:11.923Z
Link: CVE-2026-9278
No data.
Status : Received
Published: 2026-06-15T08:16:22.200
Modified: 2026-06-15T08:16:22.200
Link: CVE-2026-9278
No data.
OpenCVE Enrichment
Updated: 2026-06-15T09:30:03Z
Weaknesses