# Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms <= 1.26.14 - Unauthenticated HTML Injection in Email Notifications via Referral Link and IP Address

- **ID:** WPSEC-2026-0617
- **Plugin:** Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms (`happyforms`), https://wordpress.org/plugins/happyforms/
- **Affected versions:** all versions before 1.26.15
- **Fixed in:** 1.26.15 (Update to 1.26.15 or later.)
- **Severity:** Low 3.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-80
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/happyforms
- **Fix released:** 2026-07-14
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0617/

## Description

The Happyforms plugin for WordPress is vulnerable to HTML Injection via the referral link and IP address values in email notifications in all versions up to, and including, 1.26.14. This is due to insufficient escaping of the client referer and submitter IP address in the owner notification and submitter confirmation email templates. This makes it possible for unauthenticated attackers who submit a form to inject arbitrary HTML into emails sent to the site owner and the submitter. Exploitation requires that the form is configured to include the referral link or submitter IP address in its notification or confirmation emails, and that a recipient opens the email.

## References

- https://wpsec.com/vuln/WPSEC-2026-0617/
- https://plugins.svn.wordpress.org/happyforms/tags/1.26.15/
- https://wordpress.org/plugins/happyforms/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0617/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
