CVE-2026-97301: WordPress Cool Formkit Lite plugin <= 2.7.8 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions.
Affected Software
1 affected component
WordPress Cool Formkit Lite<=2.7.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Cool Formkit Lite pluginto a version that resolves this vulnerability.Fixed in 2.7.9
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is described as contributor-level XSS, and the vector specifies PR:L. An attacker needs low-privileged authenticated access, such as a Contributor role.
2
Does exploitation require interaction from another user?
Yes. The vector includes UI:R, indicating that user interaction is required for exploitation.
3
Which installations are affected?
Cool Formkit Lite versions 2.7.8 and earlier are affected according to the available data.