---
id: CVE-2026-88996
title: >-
  The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms,
  Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected
  Cross-Site Scripting via 'page_title' POST Parameter via {page_title} Smart
  Tag in all v…
summary: >-
  The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms,
  Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected
  Cross-Site Scripting via 'page_title' POST Parameter via {page_title} Smart
  Tag in all v…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: smub
product: >-
  WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey
  Form, Quiz & More
affected:
  - >-
    wpforms_ai_form_builder_for_wordpress_contact_forms_payment_forms_survey_form_quiz_more
    <= 2.0.2
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T13:08:08.163'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88996'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/2.0.1.1/includes/class-process.php#L1718
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/2.0.1.1/src/Frontend/Classic.php#L297
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/2.0.1.1/src/SmartTags/SmartTag/PageTitle.php#L33
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/2.0.1.1/src/SmartTags/SmartTags.php#L482
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3709178%40wpforms-lite&new=3709178%40wpforms-lite
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/0a10570c-542a-494c-9dea-96a58b91139e?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-25T10:31:56.123505Z'
ingestedAt: '2026-09-25T08:01:56.750Z'
epss: 0.00274
epssPercentile: 0.17632
---

## Overview

The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'page_title' POST Parameter via {page_title} Smart Tag in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This is only exploitable on forms whose admin-authored confirmation message places the {page_title} Smart Tag inside an HTML attribute context.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
