<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>SureForm - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/sureform/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 05 Sep 2026 07:30:29 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/sureform/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored Cross-Site Scripting in SureForms WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-sureforms-xss/</link><pubDate>Sat, 05 Sep 2026 07:30:29 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-sureforms-xss/</guid><description>An unauthenticated Stored Cross-Site Scripting vulnerability in the SureForms WordPress plugin (up to 2.12.2) allows attackers to inject malicious scripts that execute in victim browsers.</description><content:encoded><![CDATA[<p>The SureForms - Contact Form Builder, AI Forms, Payment Form, Survey &amp; Quiz plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-18406. This flaw exists in versions 2.12.2 and earlier. The vulnerability stems from the plugin's failure to adequately sanitize user-supplied input or perform proper output escaping within its text field functionality.</p>
<p>An unauthenticated attacker can exploit this weakness by submitting malicious payloads via the plugin's text fields. Once injected, these scripts are stored on the server and executed within the context of the WordPress site whenever an administrator or another user views the compromised page. This provides an avenue for session hijacking, credential theft, or the unauthorized modification of site content. Defending against this requires immediate updates to the plugin, as the lack of input handling allows arbitrary JavaScript execution without prior authentication.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary web scripts in the browser of any user who views an affected page. This can lead to the compromise of user sessions, including those with administrative privileges, potentially resulting in full site takeover. The vulnerability affects all users of the SureForms plugin prior to version 2.12.3.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the SureForms - Contact Form Builder, AI Forms, Payment Form, Survey &amp; Quiz plugin to version 2.12.3 or the latest available release to mitigate CVE-2026-18406.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>xss</category><category>wordpress</category><category>cve-2026-18406</category></item></channel></rss>