
CVE-2026-9253 The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all ve… https://www.cve.org/CVERecord?id=CVE-2026-9253
Post summary
A stored XSS vulnerability exists in the WP Cost Estimation & Payment Forms Builder plugin for WordPress via the 'customerInfos' parameter, with no exploit, patch, or active exploitation details provided.

