Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms <= 1.26.14 - Unauthenticated HTML Injection in Email Notifications via Referral Link and IP Address
- ID
- WPSEC-2026-0617
- Plugin
- Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms (happyforms)
- Affected
- all versions before 1.26.15
- Remediation
- Update to 1.26.15 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
- Weakness
- CWE-80
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-08
- Attack surface
- Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms on WPSec AttackSurface
- Fix released
- Published
Description
The Happyforms plugin for WordPress is vulnerable to HTML Injection via the referral link and IP address values in email notifications in all versions up to, and including, 1.26.14. This is due to insufficient escaping of the client referer and submitter IP address in the owner notification and submitter confirmation email templates. This makes it possible for unauthenticated attackers who submit a form to inject arbitrary HTML into emails sent to the site owner and the submitter. Exploitation requires that the form is configured to include the referral link or submitter IP address in its notification or confirmation emails, and that a recipient opens the email.
References
- https://wpsec.com/vuln/WPSEC-2026-0617/
- https://plugins.svn.wordpress.org/happyforms/tags/1.26.15/
- https://wordpress.org/plugins/happyforms/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS