CVE-2026-5169

Inquiry form to posts or pages <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Form Header Field

2026-04-07 17:36
Muhammad Nur Ibnu Hubab

Strategic Overview

Status
Unpatched
Affected Version
<= 1.0
CVSS
4.4Medium
Weakness type
CWE-79 · Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE
CVE-2026-5169
View all Inquiry form to posts or pages vulnerabilities

At a glance

CVE-2026-5169 is a medium-severity Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Inquiry form to posts or pages WordPress plugin, affecting versions <= 1.0. It carries a CVSS score of 4.4 (reachable over the network). Exploitation requires an authenticated account at Administrator level or above. No fixed release has been reported yet; treat installations running this software as exposed. Disclosed April 2026, reported by Muhammad Nur Ibnu Hubab.

Vulnerability Overview

The Inquiry Form to Posts or Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Form Header' field in versions up to and including 1.0. This is due to insufficient input sanitization when saving via update_option() and lack of output escaping when displaying the stored value. The vulnerability exists in two locations: (1) the plugin settings page at inq_form.php line 180 where the value is echoed into an HTML attribute without esc_attr(), and (2) the front-end shortcode output at inquery_form_to_posts_or_pages.php line 139 where the value is output in HTML content without esc_html(). This makes it possible for authenticated attackers with administrator-level access to inject arbitrary web scripts that will execute whenever a user accesses the plugin settings page or views a page containing the [inquiry_form] shortcode.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, and no interaction from a victim user.

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Inquiry form to posts or pages <= 1.0 carries this weakness at update_option(), and reaching it takes an account at Administrator level or above. Cross-site scripting happens when input from a request is written into a page without being escaped for the context it lands in, so the browser parses attacker-supplied text as markup or script.

Injected script runs with the privileges of whoever views the affected page, which is how these flaws turn into administrator session theft, silent account creation or persistent backdoors in page content. No fixed build of this plugin is recorded for Inquiry form to posts or pages yet, so installs running <= 1.0 stay exposed until the vendor ships one.

Remediation

No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.

How does WordSec protect against this?

An attacker needs Administrator access first, so the firewall sees the attempt as traffic from a logged-in account: WordSec's web application firewall inspects request payloads before WordPress loads them. No patched version is recorded yet, which is the case where a filtering layer matters most, because there is nothing to update to.

  • Firewall
  • Alerts

External References

Related records

Other vulnerabilities in Inquiry form to posts or pages

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C