Vulnerability in Cool FormKit Lite – Advanced Form Builder for Elementor — CVE-2026-97301
MediumSeverity
—Estimated exploit probability
20,000+ sitesInstalls
2.7.9Fixed in
What to do now
Update Cool FormKit Lite – Advanced Form Builder for Elementor to 2.7.9 or later.
Affected versions
- Everything up to and including 2.7.8
Affected: Cool FormKit Lite – Advanced Form Builder for Elementor (plugin, extensions-for-elementor-form)
What the vulnerability is
The Cool FormKit Lite – Advanced Form Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.7.8. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.