CVE · Medium

CVE-2026-12127 — WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.10.2.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-12127 WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.10.2.1 Improper Neutralization of CRLF Sequences ('CRLF Injection') Medium 5.3 < 1.10.2.1 1.10.2.1 2026-06-30

CVE-2026-12127

The WPForms plugin for WordPress contains a flaw in its handling of reply-to addresses, where it fails to properly sanitize input from textarea fields when used with smart tags. This vulnerability allows an attacker to inject arbitrary email headers into notification emails sent by the plugin, enabling them to silently receive copies of all notifications without being explicitly mentioned. The issue affects WPForms versions up to 1.10.2.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.