CVE-2026-9278
Form Builder CP < 1.2.47 - Editor+ Stored XSS via form_structure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-side script execution, allowing authenticated users with Editor-level access and above to perform Stored Cross-Site Scripting attacks against any visitor of a page rendering the affected form, even when the `unfiltered_html` capability is disallowed (e.g. in a multisite network).
| Vendor | unknown |
| Product | form builder cp |
| Published | Jun 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown form builder cp
Be the first to know when new unknown vulnerabilities affecting unknown form builder cp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Form Builder CP
0 < 1.2.47
References
Credits
Luca Jungnickel WPScan