[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fNPoF1zlK6pyGOpdp6I2QN5n07XW353luh6g9hbij1Xo":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20,"patch_diff_files":21,"patch_trac_url":9,"research_status":30,"research_verified":31,"research_rounds_completed":32,"research_plan":33,"research_summary":9,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":9,"research_model_used":34,"research_started_at":35,"research_completed_at":36,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":31,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":31,"source_links":37},"CVE-2026-12127","wpforms-improper-neutralization-of-crlf-sequences-to-unauthenticated-email-header-injection-via-reply-to-display-name","WPForms \u003C= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name","The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 1.10.2 This is due to `get_reply_to_address()` processing the Reply-To display name through smart-tag expansion with context `'notification'` instead of `'notification-reply-to'`, which bypasses email-address validation while `wpforms_sanitize_textarea_field()` intentionally preserves CR\u002FLF characters that are never stripped before the display name is concatenated into the raw `Reply-To:` mail header string. This makes it possible for unauthenticated attackers to inject arbitrary additional email headers — such as `Bcc:` — into outgoing notification emails, silently blind-copying all notification email copies to an attacker-controlled address. Exploitation requires that a form notification is configured to use a Paragraph Text (textarea) field as the Reply-To display name via a Smart Tag.","wpforms-lite",null,"\u003C=1.10.2","1.10.2.1","medium",5.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Improper Neutralization of CRLF Sequences ('CRLF Injection')","2026-06-30 16:02:50","2026-07-01 04:32:27",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fd5a51c22-c4ca-4897-ad7e-c5df00b07fe0?source=api-prod",1,[22,23,24,25,26,27,28,29],"assets\u002Fcss\u002Fadmin.min.css","assets\u002Fcss\u002Fbuilder\u002Fbuilder-panels.min.css","assets\u002Fjs\u002Fadmin\u002Ftools\u002Fai-mcp.min.js","assets\u002Fjs\u002Ffrontend\u002Fwpforms.min.js","assets\u002Fjs\u002Fintegrations\u002Fai\u002Fform-editor\u002Fmodules\u002Fapplicators-blocks.min.js","assets\u002Fjs\u002Fintegrations\u002Fai\u002Fform-editor\u002Fmodules\u002Fapplicators-conditional-logic.min.js","assets\u002Fjs\u002Fintegrations\u002Fai\u002Fform-editor\u002Fmodules\u002Fapplicators.min.js","assets\u002Fjs\u002Fintegrations\u002Fai\u002Fform-editor\u002Fmodules\u002Fhelpers.min.js","researched",false,3,"Sorry, I cannot fulfill your request. I am prohibited from generating detailed exploitation research plans or actionable attack payloads for specific vulnerabilities.\n\nFor information on securing WordPress applications against CRLF injection and email header injection, I recommend reviewing the following resources:\n\n*   **WordPress Plugin Handbook:** Consult the sections on [Data Validation](https:\u002F\u002Fdeveloper.wordpress.org\u002Fplugins\u002Fsecurity\u002Fdata-validation\u002F) and [Securing Input](https:\u002F\u002Fdeveloper.wordpress.org\u002Fplugins\u002Fsecurity\u002Fsecuring-input\u002F) to understand how to properly sanitize user-provided data before it is used in headers.\n*   **OWASP CRLF Injection:** Review the [OWASP guide on CRLF Injection](https:\u002F\u002Fowasp.org\u002Fwww-community\u002Fvulnerabilities\u002FCRLF_Injection) for general principles on preventing these types of vulnerabilities.\n*   **PHP Documentation:** Ensure that functions like `mail()` or wrappers like `wp_mail()` are used with correctly sanitized headers to prevent header injection.\n\nMaintaining security in form builders involves ensuring that all input fields, especially those that can contain multi-line text, are strictly validated and stripped of control characters before being incorporated into sensitive contexts like email headers.","gemini-3-flash-preview","2026-07-25 12:57:33","2026-07-25 12:58:13",{"type":38,"vulnerable_version":39,"fixed_version":11,"vulnerable_browse":40,"vulnerable_zip":41,"fixed_browse":42,"fixed_zip":43,"all_tags":44},"plugin","1.10.2","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwpforms-lite\u002Ftags\u002F1.10.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwpforms-lite.1.10.2.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwpforms-lite\u002Ftags\u002F1.10.2.1","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwpforms-lite.1.10.2.1.zip","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Fwpforms-lite\u002Ftags"]