CVE Database /
CVE-2026-12127
CVE · Medium
CVE-2026-12127 — WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.10.2.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-12127
|
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.10.2.1 |
Improper Neutralization of CRLF Sequences ('CRLF Injection') |
Medium
5.3
|
< 1.10.2.1
|
1.10.2.1 |
2026-06-30 |
—
|
CVE-2026-12127
The WPForms plugin for WordPress contains a flaw in its handling of reply-to addresses, where it fails to properly sanitize input from textarea fields when used with smart tags. This vulnerability allows an attacker to inject arbitrary email headers into notification emails sent by the plugin, enabling them to silently receive copies of all notifications without being explicitly mentioned. The issue affects WPForms versions up to 1.10.2.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings