<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>FormGent – Next-Gen AI Form Builder for WordPress With Multi-Step, Quizzes, Payments &amp; More (1.9.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/formgent--next-gen-ai-form-builder-for-wordpress-with-multi-step-quizzes-payments--more-1.9.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 06 Aug 2026 13:23:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/formgent--next-gen-ai-form-builder-for-wordpress-with-multi-step-quizzes-payments--more-1.9.2/feed.xml" rel="self" type="application/rss+xml"/><item><title>Stored XSS Vulnerability in FormGent WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-08-formgent-xss/</link><pubDate>Thu, 06 Aug 2026 13:23:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-formgent-xss/</guid><description>An unauthenticated stored cross-site scripting vulnerability in FormGent versions 1.9.2 and below allows attackers to inject malicious scripts into form fields that execute upon viewing.</description><content:encoded><![CDATA[<p>The FormGent AI Form Builder plugin for WordPress (versions 1.9.2 and below) contains a critical stored cross-site scripting (XSS) vulnerability. The flaw exists due to insufficient sanitization of user-supplied data within form submission fields. Because the plugin fails to properly escape input before rendering it on administrative or public-facing pages, an unauthenticated attacker can submit malicious JavaScript payloads through the plugin's forms. Once submitted, these scripts are stored in the WordPress database and automatically execute in the browser context of any user, including administrators, who subsequently accesses the page where the form entries are displayed. This vulnerability poses a significant risk for account takeover, session theft, and unauthorized actions within the WordPress environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated attackers to perform actions on behalf of privileged users, including administrators. This can lead to full site compromise, unauthorized administrative actions, redirection of users to malicious domains, or the theft of sensitive session cookies. Organizations utilizing this plugin for public-facing forms are at high risk of exploitation from external threats.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Update the FormGent plugin to the latest version (v1.9.3 or higher) immediately to ensure proper input sanitization is applied.</li>
<li>Review WordPress administrative logs for suspicious modifications performed by non-administrator accounts.</li>
<li>Deploy the WAF rule below to detect and block malicious script injection attempts targeting the plugin's submission endpoint.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application-vulnerability</category><category>wordpress</category><category>xss</category></item></channel></rss>