CVE-2026-18409 | WPForms Pro Plugin up to 2.0.0.2 on WordPress Input Sanitization view-entry.min.js wp_kses_allowed_html data-src cross site scripting

SecurityVulns

A vulnerability marked as problematic has been reported in WPForms Pro Plugin up to 2.0.0.2 on WordPress. The impacted element is the function wp_kses_allowed_html of the file view-entry.min.js of the component Input Sanitization. This manipulation of the argument data-src causes cross site scripting.

This vulnerability is tracked as CVE-2026-18409. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More