/Vulnerability Library

FormCraft3 <= 3.9.15 - Server-Side Request Forgery

CVE-2026-65442
Verified

Description

Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.

Severity

High

CVSS Score

7.2

Exploit Probability

1%

Affected Product

formcraft3

Published Date

August 3, 2026

Template Author

dhiyaneshdk

CVE-2026-65442.yaml
7.2Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CVE ID:
cve-2026-65442
CWE ID:
cwe-918

References

https://patchstack.com/database/wordpress/plugin/formcraft/vulnerability/wordpress-formcraft-plugin-3-9-15-server-side-request-forgery-ssrf-vulnerabilityhttps://wpscan.com/vulnerability/a8ce5ff4-dd4c-411c-9b34-7824a75742b6/https://github.com/advisories/GHSA-xvfc-pj4j-wr9xhttps://nvd.nist.gov/vuln/detail/CVE-2026-65442https://nvd.nist.gov/vuln/detail/CVE-2022-0591

Remediation Steps

Update FormCraft3 to version 3.9.16 or later which adds nonce verification and authentication checks to the formcraft3_get AJAX endpoint.