{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/wpwax/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2025-15028"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments \u0026 More (1.9.2)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","wordpress","xss"],"_cs_type":"advisory","_cs_vendors":["wpwax"],"content_html":"\u003cp\u003eThe FormGent AI Form Builder plugin for WordPress (versions 1.9.2 and below) contains a critical stored cross-site scripting (XSS) vulnerability. The flaw exists due to insufficient sanitization of user-supplied data within form submission fields. Because the plugin fails to properly escape input before rendering it on administrative or public-facing pages, an unauthenticated attacker can submit malicious JavaScript payloads through the plugin's forms. Once submitted, these scripts are stored in the WordPress database and automatically execute in the browser context of any user, including administrators, who subsequently accesses the page where the form entries are displayed. This vulnerability poses a significant risk for account takeover, session theft, and unauthorized actions within the WordPress environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to perform actions on behalf of privileged users, including administrators. This can lead to full site compromise, unauthorized administrative actions, redirection of users to malicious domains, or the theft of sensitive session cookies. Organizations utilizing this plugin for public-facing forms are at high risk of exploitation from external threats.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the FormGent plugin to the latest version (v1.9.3 or higher) immediately to ensure proper input sanitization is applied.\u003c/li\u003e\n\u003cli\u003eReview WordPress administrative logs for suspicious modifications performed by non-administrator accounts.\u003c/li\u003e\n\u003cli\u003eDeploy the WAF rule below to detect and block malicious script injection attempts targeting the plugin's submission endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T13:23:56Z","date_published":"2026-08-06T13:23:56Z","id":"https://feed.craftedsignal.io/briefs/2026-08-formgent-xss/","summary":"An unauthenticated stored cross-site scripting vulnerability in FormGent versions 1.9.2 and below allows attackers to inject malicious scripts into form fields that execute upon viewing.","title":"Stored XSS Vulnerability in FormGent WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-formgent-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Wpwax","version":"https://jsonfeed.org/version/1.1"}