CVE-2026-7232 | FormCraft Plugin up to 3.9.14 on WordPress Input Sanitization formcraft-main.php html_entity_decode cross site scripting
A vulnerability, which was classified as problematic, was found in FormCraft Plugin up to 3.9.14 on WordPress. This impacts the function html_entity_decode of the file formcraft-main.php of the component Input Sanitization. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2026-7232. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More