CVE-2026-15782

WPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content

The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the OptinMonster plugin to be installed and configured with an active inline campaign that outputs matching #om-{id} markup on the target page, as the WPForms handler only fires when OptinMonster emits its 'om.Campaign.load' event.


We have discovered 477,045 live websites that are affected by CVE-2026-15782.

Run a Free Instant Scan




Affected Software

Product  WPForms
Category Form Builders
Vulnerable Domains477,045 live websites (100% of WPForms install base)
Vulnerable Versions
  • from 0 through 2.0.0.1
Vulnerable Versions Count231 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 21, 2026
  • Updated - Jul 21, 2026

Credits

  • Asaf Mozes (finder)

Website Distribution by Country

Number of websites using CVE-2026-15782
United States162,810 websites



Germany49,967 websites
France28,737 websites
GB27,376 websites
Netherlands16,884 websites
Italy15,254 websites
Spain11,919 websites
Canada11,525 websites
India9,345 websites
Australia9,329 websites

Website Distribution by TLD

Number of websites using CVE-2026-15782
.com213,724 websites
.de30,268 websites
.org26,364 websites
.co.uk16,495 websites
.nl15,317 websites
.fr13,680 websites
.it10,993 websites
.net10,877 websites
.com.au8,256 websites
.pl7,046 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15782

Top websites that are affected by CVE-2026-15782. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com United States*,***
**.*******.io Germany*,***
******.com United States*,***
************.com United States*,***
**********.com United States*,***
********.com United States*,***
****************.com United States*,***
************.com United States*,***
******.com United States*,***
******************.de Germany*,***
See full domain list

FAQ

CVE-2026-15782 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WPForms
A total of 477,045 websites have been identified as vulnerable to CVE-2026-15782, based on global website indexing conducted by WebTechSurvey.
The WPForms is affected by the CVE-2026-15782 vulnerability.
WPForms versions up to and including 2.0.0.1 are vulnerable to CVE-2026-15782.