HIGH
FormCraft
CVE published 2026-07-23
CVE-2026-7232
The FormCraft plugin for WordPress, specifically versions up to and including 3.9.14, is vulnerable to Stored Cross-Site Scripting (XSS) attacks. This vulnerability arises from inadequate input sanitization and output escaping in the handling of the '[parameter name]' parameter. The vulnerability combines both server-side and client-side weaknesses. On the server-side, composite matrix sub-field keys are [truncated]