CVE-2026-13378Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-07-11)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-07-06: 1Mentions · 2026-07-11: 3Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-11: 1Technical Details · 2026-07-11: 307-0607-11
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-061
Disclosure1
2026-07-113
Disclosure2Patch1
Full discourse4 posts
  • drak3hft7@drak3hft7
    Disclosure

    Over the past months, six additional vulnerabilities I reported on @Hacker0x01 have been assigned CVE identifiers, bringing my personal total to 19 CVEs. New CVEs: CVE-2026-4260 CVE-2026-13374 CVE-2026-13375 CVE-2026-13376 CVE-2026-13377 CVE-2026-13378 These issues have been addressed by @watchguard and are covered in the following security advisories: https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00019 #bugbounty #cybersecurity #securityresearch #cve

    Post summary

    The author announces six new CVEs that have been addressed by WatchGuard and refers readers to the respective security advisories for more details.

    1513141.9K
    3.6K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-13378 - Stored #XSS in Form Vibes #WordPress plugin. Unauthenticated attackers can inject scripts via Contact Form 7 fields. #CVSS 7.2. No patch available. Disable or replace immediately. #CVEAlert #developers #python #git #github #gitlab #WordPress #infosec https://www.valtersit.com/cve/CVE-2026-13378/

    Post summary

    The post identifies a stored XSS flaw in the Form Vibes WordPress plugin with a CVSS score of 7.2, notes that no patch exists yet, and urges users to disable or replace the plugin immediately.

    2002092
    1.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13378 The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and… https://www.cve.org/CVERecord?id=CVE-2026-13378 ----- Traducción: CVE-2026-13378 The… http://infoflow.cloud`

    Post summary

    The post announces that CVE‑2026‑13378 is a stored XSS issue in the Form Vibes WordPress plugin, providing basic technical details but no PoC, exploit, or patch information.

    0000042
    92 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-13378 The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 Form Field in all versions up to, and… https://www.cve.org/CVERecord?id=CVE-2026-13378

    Post summary

    The CVE-2026-13378 disclosure notes that the WordPress "Form Vibes" plugin is vulnerable to a stored XSS flaw via Contact Form 7, with no PoC, exploit code, or patch details included.

    00000515
    57.8K followersView on X

Explore more