CVE-2026-1454General

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 via form field submissions. This is due to insufficient input sanitization in the lfb_lead_sanitize() function which omits certain field types from its sanitization whitelist, combined with an overly permissive wp_kses() filter at output time that allows onclick attributes on anchor tags. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrator views the lead entries in the WordPress dashboard.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-11); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Mentions · 2026-03-15: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-15: 103-1103-1203-15
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-111
General1
2026-03-121
General1
2026-03-151
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-1454 The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0… https://www.cve.org/CVERecord?id=CVE-2026-1454

    Post summary

    The text announces that CVE‑2026‑1454 affects the Responsive Contact Form Builder & Lead Generation Plugin, noting stored XSS in all versions up to 2.0. It does not discuss PoC, exploitation, patches, or active attacks.

    00000179
    56.7K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-1454 - themehunk - Lead Form Builder & Contact Form - https://www.redpacketsecurity.com/cve-alert-cve-2026-1454-themehunk-lead-form-builder-contact-form/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-1454 #themehunk #lead-form-builder-and-contact-form

    Post summary

    The tweet merely announces CVE‑2026‑1454 for the themehunk Lead Form Builder & Contact Form, offering no details beyond a link.

    0000086
    3.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-1454 Stored XSS in WordPress Responsive Contact Form Builder Plugin via Form Fields https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1454

    Post summary

    The text announces a stored XSS vulnerability in a WordPress plugin, providing basic technical detail but lacking evidence of proof of concept, exploitation code, active attacks, or a patch.

    000005
    4.0K followersView on X

Explore more