CVE-2025-13159

HIGH

Flo Forms - Easy Drag & Drop Form Builder <= 1.0.43 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-13159. PoCs published by MooseLoveti.

AI-analyzed exploit summary This repository provides a detailed writeup for CVE-2025-13159, an unauthenticated stored XSS vulnerability in the Flo Forms WordPress plugin. The vulnerability allows attackers to upload malicious SVG files via an unauthenticated AJAX action, leading to script execution in the admin interface.

Description

The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG file uploads in all versions up to, and including, 1.0.43. This is due to the plugin allowing SVG file uploads via an unauthenticated AJAX endpoint (`flo_form_submit`) without proper file content validation. This makes it possible for unauthenticated attackers to upload malicious SVG files containing JavaScript that executes when an administrator views the uploaded file in the WordPress admin interface, leading to potential full site compromise.

Exploits (1)

nomisec WRITEUP
by MooseLoveti · poc
https://github.com/MooseLoveti/Flo-Forms-CVE-Report

This repository provides a detailed writeup for CVE-2025-13159, an unauthenticated stored XSS vulnerability in the Flo Forms WordPress plugin. The vulnerability allows attackers to upload malicious SVG files via an unauthenticated AJAX action, leading to script execution in the admin interface.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: Flo Forms – Easy Drag & Drop Form Builder <= 1.0.43
No auth needed
Prerequisites: Access to the WordPress admin-ajax.php endpoint · Ability to craft and upload an SVG file with embedded malicious scripts
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.1
EPSS 0.0026
EPSS Percentile 16.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
flothemesplugins/Flo Forms – Easy Drag & Drop Form Builder < 1.0.43
Published Nov 21, 2025
Tracked Since Feb 18, 2026