A vulnerability categorized as problematic has been discovered in smub WPForms Plugin up to 2.0.0.1 on WordPress. Affected is an unknown function of the component Post Content. The manipulation of the argument data-sitekey results in cross site scripting.
This vulnerability was named CVE-2026-15782. The attack may be performed from remote. There is no available exploit.