PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-84744 WPForms CVE debrief

CVE-2026-84744 is a medium-severity vulnerability in the WPForms Lite WordPress plugin, allowing unauthenticated users to execute arbitrary shortcodes and read details of attachments belonging to non-public posts. The vulnerability affects versions from 1.5.0.1 to 2.0.2. Defenders should assess exposure and prioritize updates to prevent potential shortcode execution and unauthorized access to attachment details. This vulnerability has significant implications for WordPress installations using WPForms Lite, as it could lead to unauthorized actions and data exposure.

Vendor
WPForms
Product
WPForms Lite
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-28
Original CVE updated
2026-09-28
Advisory published
2026-09-28
Advisory updated
2026-09-28

Who should care

Defenders responsible for WordPress installations, particularly those using WPForms Lite, should assess exposure and prioritize updates to prevent potential shortcode execution and unauthorized access to attachment details.

Why it matters

CVE-2026-84744 is a medium-severity vulnerability in WPForms Lite that allows unauthenticated users to execute arbitrary shortcodes and access attachment details. Defenders should prioritize verifying and updating WPForms Lite installations to prevent potential shortcode execution and unauthorized access.

  • Potential execution of arbitrary shortcodes registered on the site
  • Unauthorized access to details of attachments belonging to non-public posts

Technical summary

The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts. This vulnerability is particularly concerning because it could allow attackers to perform actions that would normally be restricted to authenticated users, potentially leading to unauthorized data access or modifications.

Defensive priority

Defenders should prioritize verifying and updating WPForms Lite installations to prevent potential shortcode execution and unauthorized access to attachment details.

Recommended defensive actions

  • Verify WPForms Lite version and update to a fixed version if necessary
  • Review and restrict shortcode execution permissions
  • Monitor for potential unauthorized access to attachment details
  • Confirm whether affected WPForms Lite deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions and remediation is limited. Further verification is needed to confirm the scope of affected systems and to apply necessary updates or mitigations. The WPForms Lite plugin's failure to remove shortcode delimiters from submitted field values before rendering them back into the form presents a risk of arbitrary shortcode execution. Defenders should verify WPForms Lite installations and review shortcode execution permissions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-84744 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-84744

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-84744 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-84744

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.