---
id: CVE-2026-84744
title: >-
  The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove
  shortcode delimiters from submitted field values before writing them back into
  the rendered form, allowing unauthenticated users to execute arbitrary
  shortcodes regi…
summary: >-
  The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove
  shortcode delimiters from submitted field values before writing them back into
  the rendered form, allowing unauthenticated users to execute arbitrary
  shortcodes regi…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-94
product: WPForms
affected:
  - WPForms >= 1.5.0.1 < 2.0.2.1
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T07:17:20.827'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84744'
references:
  - url: 'https://wpscan.com/vulnerability/99c4a9fc-114e-4d39-80aa-0e9544125794/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T07:04:53.492Z'
---

## Overview

The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
