CVE-2026-19857

The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML, allowing unauthenticated visitors to have arbitrary shortcodes, with attacker-chosen attributes, executed server-side on any page displaying an affected form.
Configurations

No configuration.

History

16 Sep 2026, 18:17

Type Values Removed Values Added
CWE CWE-74

Information

Published : 2026-09-16 07:16

Updated : 2026-09-16 20:25


NVD link : CVE-2026-19857

Mitre link : CVE-2026-19857

CVE.ORG link : CVE-2026-19857


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')