PatchSiren cyber security CVE debrief
CVE-2026-101921 smub CVE debrief
CVE-2026-101921 is a reflected cross-site scripting vulnerability in WPForms, a WordPress plugin. The vulnerability exists in versions up to and including 2.0.2.1 and allows unauthenticated attackers to inject arbitrary web scripts via the 'query_var' Smart Tag in an iframe srcdoc attribute. This vulnerability can be exploited if a site administrator has previously saved a form whose description embeds a {query_var} Smart Tag inside an iframe srcdoc attribute and has enabled Show Description on a public-facing page. Successful exploitation requires user interaction, such as clicking on a link. WPForms plugin users should verify their installations and review user-input data to to
- Vendor
- smub
- Product
- WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More
- CVSS
- MEDIUM 4.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-10
- Original CVE updated
- 2026-10-10
- Advisory published
- 2026-10-10
- Advisory updated
- 2026-10-10
Who should care
WordPress administrators and users of the WPForms plugin should assess their exposure and take necessary actions to prevent exploitation. This includes verifying WPForms installations, reviewing user-input data, and implementing additional security measures to prevent cross-site scripting attacks. Security teams should prioritize verifying and updating WPForms installations to prevent exploitation and review user-input data to prevent cross-site scripting.
Why it matters
CVE-2026-101921 is a reflected cross-site scripting vulnerability in WPForms that allows unauthenticated attackers to inject arbitrary web scripts. Defenders should prioritize verifying and updating WPForms installations and review user-input data to prevent exploitation.
- Attackers may inject malicious scripts, potentially leading to user exploitation
- Successful exploitation requires user interaction, such as clicking a link
- Verify and update WPForms installations to prevent exploitation
- Review and sanitize user-input data in WPForms to prevent cross-site scripting
Technical summary
The WPForms plugin for WordPress is vulnerable to reflected cross-site scripting via the 'query_var' Smart Tag in an iframe srcdoc attribute. This allows unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability is caused by insufficient input sanitization and output escaping in the WPForms plugin. Exploitation requires a site administrator to have previously saved a form with a {query_var} Smart Tag inside an iframe srcdoc attribute and enabled Show Description on a public-facing page. WPForms plugin users should review compensating controls for exposed systems while remediation
Defensive priority
Defenders should prioritize verifying and updating WPForms installations to prevent exploitation.
Recommended defensive actions
- Verify WPForms version and update to a patched version if necessary
- Review and sanitize user-input data in WPForms
- Implement additional security measures to prevent cross-site scripting attacks
- Confirm whether affected WPForms product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The vulnerability is caused by insufficient input sanitization and output escaping in the WPForms plugin. Exploitation requires a site administrator to have previously saved a form with a {query_var} Smart Tag inside an iframe srcdoc attribute and enabled Show Description on a public-facing page.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-101921 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-101921
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-101921 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-101921
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
WPForms <= 2.0.2.1 - Reflected Cross-Site Scripting via 'query_var' Smart Tag in iframe srcdoc A
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/101xxx/CVE-2026-101921.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/2.0.2.1/src/SmartTags/SmartTags.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/2.0.2.1/src/SmartTags/SmartTag/QueryVar.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/2.0.2.1/src/Frontend/Classic.php
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://plugins.trac.wordpress.org/changeset/3730630/wpforms-lite/trunk/src/SmartTags/SmartTags.php
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.