CVE-2026-84744: WPForms Lite 1.5.0.1 - 2.0.2 - Unauthenticated Arbitrary Shortcode Execution via Form Field Repopulation
The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts.
Affected Software
Event History
Frequently Asked Questions
Which sites are exposed to meaningful impact?
Sites using WPForms Lite versions 1.5.0.1 through 2.0.2 are affected. The disclosed impact depends on the shortcodes registered on the site and includes disclosure of attachment details for non-public posts.
What does an attacker need to exploit this issue?
An attacker does not need authentication or user interaction. They need to submit form field values containing shortcode delimiters so the value is written back into a rendered form and processed.
Are default installations necessarily affected?
The vulnerable plugin versions are affected, but the practical impact depends on which shortcodes are registered on the WordPress site. The available information specifically identifies attachment-detail disclosure for attachments associated with non-public posts.