{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/repeater-fields-for-elementor-forms--2.2.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:repeater_fields_for_elementor_forms_project:repeater_fields_for_elementor_forms:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-94573"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Repeater Fields for Elementor Forms (\u003c= 2.2.7)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in all versions up to and including 2.2.7. The vulnerability stems from insufficient input sanitization and output escaping within the plugin's handling of repeater field values. This flaw allows unauthenticated remote attackers to inject malicious JavaScript into form entries stored by the plugin. When an administrator or another user views the submitted form data within the WordPress dashboard or a front-end display, the injected script executes in the context of the victim's session. This can lead to unauthorized actions performed on behalf of the victim, session hijacking, or defacement of the affected WordPress site.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browser of users viewing the injected content. This poses a significant risk to site integrity and user security, potentially facilitating account takeover or unauthorized administrative actions. The vulnerability affects all users running plugin versions 2.2.7 and earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the Repeater Fields for Elementor Forms plugin to the latest available version (beyond 2.2.7) to patch the underlying sanitization flaw. Monitor web server logs for HTTP POST requests directed at form submission endpoints that contain suspicious script tags or JavaScript event handlers.\u003c/p\u003e\n","date_modified":"2026-09-25T08:58:25Z","date_published":"2026-09-25T08:58:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-94573/","summary":"The Repeater Fields for Elementor Forms plugin for WordPress contains a Stored XSS vulnerability allowing unauthenticated attackers to inject arbitrary web scripts through unsanitized repeater field inputs.","title":"Stored Cross-Site Scripting in Repeater Fields for Elementor Forms","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-94573/"}],"language":"en","title":"CraftedSignal Threat Feed - Repeater Fields for Elementor Forms (\u003c= 2.2.7)","version":"https://jsonfeed.org/version/1.1"}