plugin

Contact Form Add Vulnerabilities

9 known security issues reported for the Contact Form Add WordPress plugin. Most recent disclosed Nov 7, 2023.

1 high 3 medium

Running Contact Form Add on your site? Check whether your installed version is affected.

Scan your site free

Form Builder | Create Responsive Contact Forms [contact-form-add] <= 1.9.9.0 (unfixed + closed)

unknown

[en] Improper Neutralization of Formula Elements in a CSV File vulnerability in Muneeb Form Builder | Create Responsive Contact Forms.This issue affects Form Builder | Create Responsive Contact Forms: from n/a through 1.9.9.0.

Affected:
up to 1.9.9.0
Fix:
No patched version reported
Disclosed:
Nov 7, 2023

CVE-2023-23796 on NVD →

Form Builder <= 1.9.9.0 - Unauthenticated CSV Injection

high

The Form Builder plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.9.9.0. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable config...

CVSS:
8.3
Affected:
up to 1.9.9.0
Fix:
No patched version reported
Disclosed:
Jun 28, 2023

CVE-2023-23796 on NVD →

Form Builder | Create Responsive Contact Forms [contact-form-add] <= 1.9.9.0 (unfixed + closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Muneeb Form Builder plugin <= 1.9.9.0 versions.

Affected:
up to 1.9.9.0
Fix:
No patched version reported
Disclosed:
Jun 22, 2023

CVE-2023-23795 on NVD →

Form Builder <= 1.9.9.0 - Cross-Site Request Forgery

medium

The Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.9.9.0. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site admin...

CVSS:
6.5
Affected:
up to 1.9.9.0
Fix:
No patched version reported
Disclosed:
Jun 19, 2023

CVE-2023-23795 on NVD →

Form Builder | Create Responsive Contact Forms [contact-form-add] < 1.9.8.4 (closed)

unknown

[en] The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed

Affected:
up to 1.9.8.4
Fixed in:
1.9.8.4
Disclosed:
Sep 6, 2021

CVE-2021-24513 on NVD →

Form Builder | Create Responsive Contact Forms <= 1.9.8.4 - Cross-Site Scripting

medium

The Form Builder | Create Responsive Contact Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘form_id’ parameter in versions up to, and including, 1.9.8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...

CVSS:
6.1
Affected:
up to 1.9.8.4
Fixed in:
1.9.8.5
Disclosed:
Aug 9, 2021

Form Builder <= 1.9.8.3 - Authenticated Stored Cross-Site Scripting

medium

The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed

CVSS:
5.5
Affected:
up to 1.9.8.3
Fixed in:
1.9.8.4
Disclosed:
Aug 9, 2021

CVE-2021-24513 on NVD →

Form Builder | Create Responsive Contact Forms [contact-form-add] < 1.9.8.5 (closed)

unknown

The Form Builder | Create Responsive Contact Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘form_id’ parameter in versions up to, and including, 1.9.8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...

Affected:
up to 1.9.8.5
Fixed in:
1.9.8.5
Disclosed:
Aug 9, 2021

Form Builder | Create Responsive Contact Forms [contact-form-add] < 1.9.8.5 (closed)

unknown

The plugin does not properly sanitise and escape its from_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue.

Affected:
up to 1.9.8.5
Fixed in:
1.9.8.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database