CVE-2026-3652

ARForms <= 7.1.3 - Unauthenticated Stored Cross-Site Scripting via 'value' Parameter

The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save_incomplete_form_data` AJAX action in all versions up to, and including, 7.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute whenever an administrator views the "Partial Filled Form Entries" page in the ARForms dashboard.


We have discovered 419 live websites that are affected by CVE-2026-3652.

Run a Free Instant Scan




Affected Software

Product  Arforms Pro
Category Wordpress Plugins
Vulnerable Domains419 live websites (100% of Arforms Pro install base)
Vulnerable Versions
  • from 0 through 7.1.3
Vulnerable Versions Count37 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jun 24, 2026
  • Updated - Jun 24, 2026

Credits

  • Phú (finder)

Website Distribution by Country

Number of websites using CVE-2026-3652
United States130 websites



Germany53 websites
GB34 websites
Italy30 websites
France22 websites
Netherlands13 websites
India9 websites
Canada8 websites
Spain7 websites
Austria7 websites

Website Distribution by TLD

Number of websites using CVE-2026-3652
.com189 websites
.de37 websites
.org22 websites
.it21 websites
.co.uk17 websites
.nl13 websites
.net11 websites
.at7 websites
.fr7 websites
.es6 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-3652

Top websites that are affected by CVE-2026-3652. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.com United States**,***
*******.**.uk GB***,***
***************.nl Netherlands***,***
********.org United States***,***
*****.de Germany***,***
************.com United States***,***
**********.com Germany***,***
******************.fr France***,***
**********.it Italy*,***,***
*******.************.com United States*,***,***
See full domain list

FAQ

CVE-2026-3652 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Arforms Pro
A total of 419 websites have been identified as vulnerable to CVE-2026-3652, based on global website indexing conducted by WebTechSurvey.
The Arforms Pro is affected by the CVE-2026-3652 vulnerability.
Arforms Pro versions up to and including 7.1.3 are vulnerable to CVE-2026-3652.