FormCraft3 <= 3.9.15 - Server-Side Request Forgery
CVE-2026-65442
Verified
Description
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
Severity
High
CVSS Score
7.2
Exploit Probability
1%
Affected Product
formcraft3
Published Date
August 3, 2026
Template Author
dhiyaneshdk
CVE-2026-65442.yaml
7.2Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CVE ID:
cve-2026-65442
CWE ID:
cwe-918
References
https://patchstack.com/database/wordpress/plugin/formcraft/vulnerability/wordpress-formcraft-plugin-3-9-15-server-side-request-forgery-ssrf-vulnerabilityhttps://wpscan.com/vulnerability/a8ce5ff4-dd4c-411c-9b34-7824a75742b6/https://github.com/advisories/GHSA-xvfc-pj4j-wr9xhttps://nvd.nist.gov/vuln/detail/CVE-2026-65442https://nvd.nist.gov/vuln/detail/CVE-2022-0591
Remediation Steps
Update FormCraft3 to version 3.9.16 or later which adds nonce verification and authentication checks to the formcraft3_get AJAX endpoint.