CVE-2026-39766HIGH NVDCVSS Score 7.1Severity HIGHPublished Oct 06, 2026Vendor unknownDescriptionUnauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions.Referenceshttps://patchstack.com/database/wordpress/plugin/arforms/vulnerability/wordpress-arforms-plugin-7-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve