Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms <= 1.26.14 - Unauthenticated HTML Injection in Email Notifications via Referral Link and IP Address

Low 3.1 CWE-80Fixed in 1.26.15
ID
WPSEC-2026-0617
Plugin
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms (happyforms)
Affected
all versions before 1.26.15
Remediation
Update to 1.26.15 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Weakness
CWE-80
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-08
Attack surface
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms on WPSec AttackSurface
Fix released
Published

Description

The Happyforms plugin for WordPress is vulnerable to HTML Injection via the referral link and IP address values in email notifications in all versions up to, and including, 1.26.14. This is due to insufficient escaping of the client referer and submitter IP address in the owner notification and submitter confirmation email templates. This makes it possible for unauthenticated attackers who submit a form to inject arbitrary HTML into emails sent to the site owner and the submitter. Exploitation requires that the form is configured to include the referral link or submitter IP address in its notification or confirmation emails, and that a recipient opens the email.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0