← WordPress Vulnerabilities
WordPress security by component

FormCraft

FormCraft is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: formcraft

CVE-2026-65442: FormCraft permits unauthenticated server-side request forgery

FormCraft through 3.9.15 lets an unauthenticated attacker supply a destination that reaches an undisclosed server-side fetch operation. This can make the WordPress server send requests to attacker-selected or internal resources. The Patchstack CNA record does not disclose the route, action, URL parameter, fetch function, allowed schemes or response visibility.

PublishedJul 27, 2026
Known safe version3.9.16
Safe version
Jul 27, 2026 CVE-2026-65442
FormCraft permits unauthenticated server-side request forgery
FormCraft through 3.9.15 lets an unauthenticated attacker supply a destination that reaches an undisclosed server-side fetch operation. This can make the WordPress server send requests to attacker-selected or internal resources. The Patchstack CNA record does not disclose the route, action, URL parameter, fetch function, allowed schemes or response visibility.
3.9.16
CVE7.2
NVDPending
Jul 23, 2026 CVE-2026-7232
FormCraft: Cross-site scripting
FormCraft is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.9.14.
> 3.9.14
CVE7.2
NVDPending
Feb 18, 2025 CVE-2025-0817
FormCraft: Cross-site scripting
FormCraft is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.2
NVD6.1
Feb 18, 2025 CVE-2024-13783
FormCraft: A security weakness
FormCraft is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Aug 30, 2023 CVE-2023-3501
FormCraft: Cross-site scripting
FormCraft is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jun 27, 2023 CVE-2023-2592
FormCraft: SQL injection
FormCraft is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2
Jun 08, 2022 CVE-2022-1647
FormCraft: Cross-site scripting
FormCraft is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Sep 10, 2019 CVE-2017-18600
Formcraft: Cross-site scripting
Formcraft is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Aug 23, 2017 CVE-2017-13137
Formcraft: SQL injection
Formcraft is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Dec 20, 2013 CVE-2013-7187
Formcraft: SQL injection
Formcraft is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVD7.5