Medium · 5.4 WordPress CVE-2026-74991 CVE-2026-84744 CVE-2026-101921
Three WPForms Vulnerabilities Allow Unauthenticated Stripe Refunds, Shortcode Injection and Reflected XSS
Three separate vulnerabilities in the WPForms WordPress plugin let unauthenticated attackers trigger Stripe refunds and subscription cancellations, inject arbitrary shortcodes to read non-public attachment data, and execute reflected XSS on sites with specific form configurations. No vendor fix has been confirmed for any of the three issues at this time.
AI summary
WPForms is a widely used WordPress form builder plugin with a reported install base of around 5 million sites. Three distinct vulnerabilities affecting WPForms have been published, each tracked under its own CVE identifier. They involve different weaknesses: improper authorization around Stripe payment objects, insufficient sanitization of submitted form data allowing shortcode injection, and a reflected cross-site scripting issue tied to a specific smart tag configuration. This briefing summarizes what is known about each issue based on the available advisory data.
What happened
Three vulnerabilities in the WPForms plugin have been disclosed under separate CVE identifiers. CVE-2026-74991 describes a flaw where the plugin does not verify that a Stripe payment object submitted during a public form submission actually belongs to the form, allowing an unauthenticated user to trigger a full refund and immediate subscription cancellation against payments created by other applications on the site owner's Stripe account. CVE-2026-84744 describes a failure to strip shortcode delimiters from submitted field values before they are rendered back into the form, allowing unauthenticated users to execute arbitrary shortcodes already registered on the site and read details of attachments belonging to non-public posts. CVE-2026-101921 is a reflected cross-site scripting issue via an attacker-chosen key referenced by a smart tag, which requires both a site administrator to have set up a form description containing a {query_var} Smart Tag inside an iframe srcdoc attribute with the description displayed publicly, and a victim being tricked into clicking a crafted link.
Technical cause
CVE-2026-74991 is classified under CWE-284 (Improper Access Control), stemming from a missing ownership check on Stripe payment objects referenced during form submission. CVE-2026-84744 is classified under CWE-94 (Code Injection), caused by failure to remove shortcode delimiters from user-submitted field values before they are written back into the rendered form output. CVE-2026-101921 is classified under CWE-79 (Cross-Site Scripting), resulting from insufficient input sanitization and output escaping of a key value referenced by a smart tag, exploitable only in forms where a specific {query_var} Smart Tag has been embedded inside an iframe srcdoc attribute in a publicly shown form description.
Why it matters
All three issues can be triggered by unauthenticated attackers, and two (CVE-2026-74991 and CVE-2026-84744) require no user interaction at all. The Stripe issue (CVE-2026-74991) can result in unauthorized refunds and subscription cancellations affecting payments unrelated to the WPForms installation itself, which has direct financial impact for site owners using Stripe. The shortcode injection issue (CVE-2026-84744) can expose details of non-public post attachments and allow execution of any shortcode already registered on the site, which may have further consequences depending on what other plugins or themes register. The reflected XSS issue (CVE-2026-101921) requires a non-default form configuration and user interaction, which narrows its practical exploitability compared to the other two.
Who is affected
Sites running the WPForms WordPress plugin are affected. For CVE-2026-74991, versions from 1.8.8.2 up to but not including 2.0.2 are listed as affected. For CVE-2026-84744, versions from 1.5.0.1 up to but not including 2.0.2.1 are listed as affected. For CVE-2026-101921, the advisory indicates versions up to but not including 2.0.2.2 are affected; no lower bound is specified in the available data. Sites using Stripe payment integration are specifically exposed to the impact described in CVE-2026-74991, and sites that display form descriptions containing the specific smart tag/iframe configuration are exposed to CVE-2026-101921.
Affected versions
CVE-2026-74991: WPForms versions 1.8.8.2 and later, prior to 2.0.2. CVE-2026-84744: WPForms versions 1.5.0.1 and later, prior to 2.0.2.1. CVE-2026-101921: WPForms versions prior to 2.0.2.2 (no introduced version specified in the source data).
Fixes and mitigation
The fact package does not confirm that a patched version has been released and made available for any of the three vulnerabilities; fix_available is marked false for all three advisories, even though version boundaries such as 2.0.2, 2.0.2.1 and 2.0.2.2 appear in the affected-range data as the point at which each issue is described as resolved. Given this inconsistency between the listed version boundaries and the explicit fix_available flag, we cannot confirm with certainty whether an update addressing these issues is currently available. Site owners should check the WPForms plugin changelog directly within their WordPress admin dashboard or on the official plugin page for the latest available version and update promptly once a fix is confirmed.
Recommended action
Update the WPForms plugin to the latest available version as soon as possible and verify in the changelog that it addresses CVE-2026-74991, CVE-2026-84744, and CVE-2026-101921. If Stripe payment forms are in use, review recent Stripe transaction logs for unexpected refunds or subscription cancellations. Review any form descriptions that use smart tags inside iframe srcdoc attributes and disable public display of such descriptions until an update is confirmed. Until a fix is verified, consider limiting public exposure of affected forms where feasible.
PatchBriefing score
5.4 / 10 · Medium
Official CVSS: 6.8
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Why this score
The three issues carry different Patchwire scores reflecting their distinct characteristics. CVE-2026-74991 scores 5.4, driven by a CVSS base score of 6.8 and the fact that it is unauthenticated, requires no user interaction, and currently has no confirmed fix, against a plugin with a large install base. CVE-2026-84744 scores 5.2 based on a CVSS base score of 6.5 with the same unauthenticated, no-interaction, no-fix characteristics. CVE-2026-101921 scores lower at 4.0, reflecting its lower CVSS base score of 4.7 and the requirement for user interaction, which reduces its practical exploitability compared to the other two. None of the three are flagged as known exploited or as having public exploit code.
Affected versions
- WPForms ≥ 1.8.8.2 < 2.0.2
- vulnerable
- WPForms ≥ 1.5.0.1 < 2.0.2.1
- vulnerable
- WPForms < 2.0.2.2
- vulnerable
Reported fixes
The fact package does not confirm that a patched version has been released and made available for any of the three vulnerabilities; fix_available is marked false for all three advisories, even though version boundaries such as 2.0.2, 2.0.2.1 and 2.0.2.2 appear in the affected-range data as the point at which each issue is described as resolved. Given this inconsistency between the listed version boundaries and the explicit fix_available flag, we cannot confirm with certainty whether an update addressing these issues is currently available. Site owners should check the WPForms plugin changelog directly within their WordPress admin dashboard or on the official plugin page for the latest available version and update promptly once a fix is confirmed.
How this was built
6 source records were collected, matched and used to prepare the report above.
-
WPVulnerability database
-
NVD (NIST) database
-
WPVulnerability database
-
NVD (NIST) database
-
WPVulnerability database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email