{"id":"CVE-2026-19857","title":"The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML, allowing unauthenticated visitors to…","summary":"The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML, allowing unauthenticated visitors to…","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-74"],"product":"Formidable Forms","affected":["formidable_forms >= 6.34 < 6.35"],"published":"2026-09-16","updated":"2026-09-16","sourceUpdated":"2026-09-16T20:25:29.240","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-19857","references":[{"url":"https://wpscan.com/vulnerability/5ff439f4-aa99-4198-b908-0cf098656cf7/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-16T17:40:23.986926Z"},"ingestedAt":"2026-09-16T06:51:06.263Z","epss":0.00188,"epssPercentile":0.08705,"slug":"CVE-2026-19857","body":"## Overview\n\nThe Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML, allowing unauthenticated visitors to have arbitrary shortcodes, with attacker-chosen attributes, executed server-side on any page displaying an affected form.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":38,"depthScoreParts":{"impact":26.4,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":205651,"id":"CVE-2026-19857","ts":1789581739843,"field":"exploit_available","old":"false","new":"true"}]}