{
 "id": "WPSEC-2026-0520",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0520/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0520/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0520/index.md",
 "title": "WPForms <= 2.0.2.1 - Unauthenticated Reflected Cross-Site Scripting via Smart Tags",
 "description": "The WPForms plugin for WordPress is vulnerable to Cross-Site Scripting via Smart Tag values in all versions up to, and including, 2.0.2.1. Smart Tag values placed in embedded markup in Confirmation messages or form descriptions were escaped only with attribute escaping, which does not protect event-handler attributes, script element bodies, srcdoc documents, xlink:href, or SVG animation values. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser, for example through values supplied by {query_var} in a crafted URL or through submitted field values. Exploitation requires that a form author has placed a Smart Tag in one of these contexts, and that a victim visits the crafted link or views the affected output.",
 "plugin": {
  "slug": "wpforms-lite",
  "name": "WPForms",
  "full_name": "WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More",
  "wordpress_org": "https://wordpress.org/plugins/wpforms-lite/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wpforms-lite/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wpforms-lite"
 },
 "type": "XSS",
 "cwe": [
  "CWE-79"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.7,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "2.0.2.2",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 2.0.2.2"
  ]
 },
 "introduced_in": null,
 "fixed_in": "2.0.2.2",
 "remediation": "Update to 2.0.2.2 or later.",
 "fix_released": "2026-10-06T11:14:37+00:00",
 "published": "2026-10-07T11:46:41+00:00",
 "updated": "2026-10-06T14:18:48.713788+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0520/",
  "https://plugins.svn.wordpress.org/wpforms-lite/tags/2.0.2.2/",
  "https://wordpress.org/plugins/wpforms-lite/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wpforms-lite",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "High",
  "affected_versions": "High",
  "as_of": "2026-10-07"
 }
}