<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Repeater Fields for Elementor Forms (&lt;= 2.2.7) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/repeater-fields-for-elementor-forms--2.2.7/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 25 Sep 2026 08:58:25 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/repeater-fields-for-elementor-forms--2.2.7/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in Repeater Fields for Elementor Forms</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-94573/</link><pubDate>Fri, 25 Sep 2026 08:58:25 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-94573/</guid><description>The Repeater Fields for Elementor Forms plugin for WordPress contains a Stored XSS vulnerability allowing unauthenticated attackers to inject arbitrary web scripts through unsanitized repeater field inputs.</description><content:encoded><![CDATA[<p>The Repeater Fields for Elementor Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) in all versions up to and including 2.2.7. The vulnerability stems from insufficient input sanitization and output escaping within the plugin's handling of repeater field values. This flaw allows unauthenticated remote attackers to inject malicious JavaScript into form entries stored by the plugin. When an administrator or another user views the submitted form data within the WordPress dashboard or a front-end display, the injected script executes in the context of the victim's session. This can lead to unauthorized actions performed on behalf of the victim, session hijacking, or defacement of the affected WordPress site.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the browser of users viewing the injected content. This poses a significant risk to site integrity and user security, potentially facilitating account takeover or unauthorized administrative actions. The vulnerability affects all users running plugin versions 2.2.7 and earlier.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the Repeater Fields for Elementor Forms plugin to the latest available version (beyond 2.2.7) to patch the underlying sanitization flaw. Monitor web server logs for HTTP POST requests directed at form submission endpoints that contain suspicious script tags or JavaScript event handlers.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>