CVE detail
CVE-2026-12127
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 1.10.2 This is due to `get_reply_to_address()` processing the Reply-To display name through smart-tag expansion with context `'notification'` instead of `'notification-reply-to'`, which bypasses email-address validation while `wpforms_sanitize_textarea_field()` intentionally preserves CR/LF characters that are never stripped before the display name is concatenated into the raw `Reply-To:` mail header string. This makes it possible for unauthenticated attackers to inject arbitrary additional email headers — such as `Bcc:` — into outgoing notification emails, silently blind-copying all notification email copies to an attacker-controlled address. Exploitation requires that a form notification is configured to use a Paragraph Text (textarea) field as the Reply-To display name via a Smart Tag.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 12
- within the 30d window
- Peak daily
- 11
- highest bucket
Evidence
Source links by recency
12 source links · newest first
- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 29, 2026 to July 5, 2026)Wordfence
tory Pro Slider Revolution 7.0.0-7.0.16 - Unauthenticated Stored Cross-Site Scripting 7.2 CVSS Rating 7.2 (High) CVE-ID CVE-2026-57678 Patch Status Patched Published Jun 30, 2026 Affected Software Slider Revolution [revslider] Researcher daroo More Details > SpaLab | Beauty Salon WordPress Survey Maker by AYS Timetics – Appointment Booking Calendar & S
vendorwww.wordfence.comJul 9, 2026, 3:39 PM - https://www.wordfence.com/threat-intel/vulnerabilities/id/d5a51c22-c4ca-4897-ad7e-c5df00b07fe0?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJul 1, 2026, 5:16 AM - https://plugins.trac.wordpress.org/changeset?old_path=%2Fwpforms-lite/tags/1.10.2&new_path=%2Fwpforms-lite/tags/1.10.2.1plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 1, 2026, 5:16 AM - https://plugins.trac.wordpress.org/changeset/3586095/wpforms-lite/trunk/src/Emails/Mailer.phpplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 1, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.1.1/src/Emails/Notifications.php#L1138plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 1, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.1.1/src/Emails/Notifications.php#L1098plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 1, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.1.1/src/Emails/Mailer.php#L368plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 1, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.1.1/includes/fields/class-textarea.php#L326plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 1, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.0.2/src/Emails/Notifications.php#L1138plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 1, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.0.2/src/Emails/Notifications.php#L1098plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 1, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.0.2/src/Emails/Mailer.php#L368plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 1, 2026, 5:16 AM - https://plugins.trac.wordpress.org/browser/wpforms-lite/tags/1.10.0.2/includes/fields/class-textarea.php#L326plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJul 1, 2026, 5:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-15157CVSS 4.2 · Medium
undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, f…
- CVE-2026-12357CVSS 7.2 · High
Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affect…
- CVE-2026-59920CVSS 6.5 · Medium
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's STOMP encoder ( StompSubframeEncoder ) does not…
- CVE-2026-59919CVSS 5.5 · Medium
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder ( HAProxyMessageEncoder ) writes…
- CVE-2026-59921CVSS 5.7 · Medium
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bo…
- CVE-2026-57511CVSS 6.3 · Medium
SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject arbitrary SMTP headers by including CRLF sequences in the…