PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94573 addonsorg CVE debrief

The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts, which can be executed when a user accesses an affected page. Defenders should assess exposure and prioritize verification and updates to prevent potential XSS attacks. The CVE record and NVD entry provide details on the vulnerability, but further verification is needed to confirm affected versions and potential impact.

Vendor
addonsorg
Product
Repeater Fields for Elementor Forms
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders responsible for WordPress installations with the Repeater Fields for Elementor Forms plugin should assess exposure and prioritize verification and updates to prevent potential XSS attacks. Roles responsible for WordPress installations with this plugin should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Why it matters

Defenders should care about CVE-2026-94573 because it involves a high-severity vulnerability in the Repeater Fields for Elementor Forms plugin for WordPress, allowing for potential Stored Cross-Site Scripting attacks. Roles responsible for WordPress installations with this plugin should assess exposure and prioritize verification and updates to prevent potential XSS attacks.

  • Potential for unauthenticated attackers to inject arbitrary web scripts
  • Possible execution of injected scripts when users access affected pages
  • Need for verification of affected versions and potential impact
  • Priority for updating the Repeater Fields for Elementor Forms plugin

Technical summary

The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Field Value in all versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts, which can be executed when a user accesses an affected page. The vulnerability's technical details involve the plugin's failure to properly sanitize and escape user input, allowing for potential XSS attacks.

Defensive priority

Defenders should prioritize verifying and updating the Repeater Fields for Elementor Forms plugin to prevent potential XSS attacks.

Recommended defensive actions

  • Verify and update the Repeater Fields for Elementor Forms plugin to the latest version
  • Monitor for potential XSS attacks on affected systems
  • Implement additional security measures to prevent similar vulnerabilities
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but further verification is needed to confirm affected versions and potential impact. Defenders should verify the presence of the Repeater Fields for Elementor Forms plugin in their WordPress installations and check for any existing XSS attacks. The vulnerability's severity and potential impact should be assessed, and updates or mitigations should be planned through normal change control.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94573 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94573

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94573 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94573

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.