{
 "id": "WPSEC-2026-0617",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0617/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0617/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0617/index.md",
 "title": "Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms <= 1.26.14 - Unauthenticated HTML Injection in Email Notifications via Referral Link and IP Address",
 "description": "The Happyforms plugin for WordPress is vulnerable to HTML Injection via the referral link and IP address values in email notifications in all versions up to, and including, 1.26.14. This is due to insufficient escaping of the client referer and submitter IP address in the owner notification and submitter confirmation email templates. This makes it possible for unauthenticated attackers who submit a form to inject arbitrary HTML into emails sent to the site owner and the submitter. Exploitation requires that the form is configured to include the referral link or submitter IP address in its notification or confirmation emails, and that a recipient opens the email.",
 "plugin": {
  "slug": "happyforms",
  "name": "Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms",
  "full_name": "Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms",
  "wordpress_org": "https://wordpress.org/plugins/happyforms/",
  "advisories_url": "https://wpsec.com/vuln/plugin/happyforms/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/happyforms"
 },
 "type": "CONTENT INJECTION",
 "cwe": [
  "CWE-80"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 3.1,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N",
  "severity": "Low"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.26.15",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.26.15"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.26.15",
 "remediation": "Update to 1.26.15 or later.",
 "fix_released": "2026-07-14T21:07:26+00:00",
 "published": "2026-10-08T07:44:03+00:00",
 "updated": "2026-10-08T07:41:08.629158+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0617/",
  "https://plugins.svn.wordpress.org/happyforms/tags/1.26.15/",
  "https://wordpress.org/plugins/happyforms/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/happyforms",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-08"
 }
}