CVE-2026-84744
Published 28 September 2026 · tracked since 28 September 2026
Description
The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belongin
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-91206 MEDIUM 6.1
- CVE-2026-82382 MEDIUM 6.1
- CVE-2026-82383 HIGH 8.2
- CVE-2026-82384 CRITICAL 9.8
- CVE-2026-82385 MEDIUM 6.5
- CVE-2026-82386 HIGH 7.7
- CVE-2026-82387 MEDIUM 5.4
- CVE-2026-82546 MEDIUM 6.1
- CVE-2026-91204 MEDIUM 6.1
- CVE-2026-82375 HIGH 7.4