WordPress security changelog
MEDIUM CVE-2026-7623 Received

SureForms headingWrapper values let Contributors store JavaScript

SureForms through 2.8.1 does not adequately sanitize and escape the headingWrapper parameter used by its advanced-heading block. A Contributor-or-higher user can save attacker-controlled markup in a page through that parameter, and the block renderer places the value into the page without sufficient output escaping. The injected JavaScript executes whenever a visitor or administrator views the affected page. The published record does not disclose the exact editor request, stored block attribute path or payload encoding.

CVE / CNA score 6.4 CVSS 3.1 · security@wordfence.com
NVD score Pending NVD has not published its own CVSS assessment.
Component
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz
Plugin slug
sureforms
Affected
<= 2.8.1
Safe version
2.8.2
Published
Aug 01, 2026
Weakness
CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

This CVE was published Aug 01, 2026 and is one of 14 known issues for this plugin.

Update, patch or deactivate.

Update SureForms to 2.8.2 or later. Review advanced-heading blocks created or edited by Contributors for unexpected headingWrapper markup, remove confirmed payloads, and invalidate administrator sessions if a privileged user viewed an affected page.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'headingWrapper' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVE / CNA vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Primary and upstream sources