plugin

Contact Form Lite Vulnerabilities

8 known security issues reported for the Contact Form Lite WordPress plugin. Most recent disclosed Jun 9, 2025.

4 medium

Running Contact Form Lite on your site? Check whether your installed version is affected.

Scan your site free

Easy Contact Form Lite <= 1.1.28 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form fields in all versions up to, and including, 1.1.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitr...

CVSS:
6.4
Affected:
up to 1.1.28
Fixed in:
1.1.29
Disclosed:
Jun 9, 2025

CVE-2025-5730 on NVD →

Contact Form Plugin [contact-form-lite] < 1.1.27

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Easy Contact Form Lite allows Stored XSS. This issue affects Easy Contact Form Lite : from n/a through 1.1.25.

Affected:
up to 1.1.27
Fixed in:
1.1.27
Disclosed:
Feb 25, 2025

CVE-2025-26962 on NVD →

Contact Form Plugin <= 1.1.25 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Contact Form Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.25 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in p...

CVSS:
6.4
Affected:
up to 1.1.25
Fixed in:
1.1.27
Disclosed:
Feb 23, 2025

CVE-2025-26962 on NVD →

Contact Form Plugin [contact-form-lite] < 1.1.25

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Form Plugin Team - GhozyLab Easy Contact Form Lite allows Stored XSS.This issue affects Easy Contact Form Lite : from n/a through 1.1.23.

Affected:
up to 1.1.25
Fixed in:
1.1.25
Disclosed:
Apr 15, 2024

CVE-2024-32147 on NVD →

Easy Contact Form Lite <= 1.1.23 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Easy Contact Form Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 1.1.23
Fixed in:
1.1.25
Disclosed:
Apr 12, 2024

CVE-2024-32147 on NVD →

Contact Form Plugin [contact-form-lite] < 4.0.2

unknown

[en] A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to...

Affected:
up to 4.0.2
Fixed in:
4.0.2
Disclosed:
Jun 16, 2022

CVE-2017-20055 on NVD →

Contact Form Plugin <= 4.0.1 - Stored Cross-Site Scripting

medium

A vulnerability classified as problematic has been found in BestWebSoft Contact Form Plugin 4.0.0. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to versi...

CVSS:
6.4
Affected:
up to 4.0.1
Fixed in:
4.0.2
Disclosed:
Mar 1, 2017

CVE-2017-20055 on NVD →

Contact Form Plugin [contact-form-lite] < 1.0.8

unknown

This WordPress Easy Contact Form Lite plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.

Affected:
up to 1.0.8
Fixed in:
1.0.8
Disclosed:
Aug 17, 2011

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database