Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] <= 4.3.5 (unfixed)
unknown
[en] Missing Authorization vulnerability in bestwebsoft Contact Form by BestWebSoft contact-form-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by BestWebSoft: from n/a through <= 4.3.5.
- Affected:
- up to 4.3.5
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-63056 on NVD →
Contact Form by BestWebSoft <= 4.3.6 - Missing Authorization
medium
The Contact Form by BestWebSoft plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 4.3.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 4.3.6
- Fixed in:
- 4.3.7
- Disclosed:
- Dec 7, 2025
CVE-2025-63056 on NVD →
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] < 4.2.9
unknown
[en] The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm_contact_address’ parameter in all versions up to, and including, 4.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...
- Affected:
- up to 4.2.9
- Fixed in:
- 4.2.9
- Disclosed:
- Apr 9, 2024
CVE-2024-2198 on NVD →
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] < 4.2.9
unknown
[en] The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm_contact_subject’ parameter in all versions up to, and including, 4.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject ar...
- Affected:
- up to 4.2.9
- Fixed in:
- 4.2.9
- Disclosed:
- Apr 9, 2024
CVE-2024-2200 on NVD →
Contact Form by BestWebSoft <= 4.2.8 - Reflected Cross-Site Scripting via cntctfrm_contact_subject
medium
The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm_contact_subject’ parameter in all versions up to, and including, 4.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...
- CVSS:
- 6.1
- Affected:
- up to 4.2.8
- Fixed in:
- 4.2.9
- Disclosed:
- Mar 13, 2024
CVE-2024-2200 on NVD →
Contact Form by BestWebSoft <= 4.2.8 - Reflected Cross-Site Scripting via cntctfrm_contact_address
medium
The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cntctfrm_contact_address’ parameter in all versions up to, and including, 4.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra...
- CVSS:
- 6.1
- Affected:
- up to 4.2.8
- Fixed in:
- 4.2.9
- Disclosed:
- Mar 13, 2024
CVE-2024-2198 on NVD →
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] < 3.82
unknown
[en] A vulnerability was found in BestWebSoft Contact Form Plugin 1.3.4 on WordPress and classified as problematic. Affected by this issue is the function bws_add_menu_render of the file bws_menu/bws_menu.php. The manipulation of the argument bwsmn_form_email leads to cross site scripting. The attack may be launched re...
- Affected:
- up to 3.82
- Fixed in:
- 3.82
- Disclosed:
- Apr 9, 2023
CVE-2014-125095 on NVD →
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] < 3.52
unknown
[en] A vulnerability, which was classified as problematic, has been found in BestWebSoft Contact Form Plugin 3.51 on WordPress. Affected by this issue is the function cntctfrm_display_form/cntctfrm_check_form of the file contact_form.php. The manipulation leads to cross site scripting. The attack may be launched remote...
- Affected:
- up to 3.52
- Fixed in:
- 3.52
- Disclosed:
- Apr 5, 2023
CVE-2013-10022 on NVD →
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] < 3.35
unknown
[en] The contact-form-plugin plugin before 3.3.5 for WordPress has XSS.
- Affected:
- up to 3.35
- Fixed in:
- 3.35
- Disclosed:
- Aug 22, 2019
CVE-2013-7481 on NVD →
Contact Form by BestWebSoft – Advanced Contact Us Form Builder for WordPress <= 4.0.1 - Cross-Site Scripting
medium
The contact-form-plugin plugin before 4.0.2 for WordPress has XSS.
- CVSS:
- 6.1
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.2
- Disclosed:
- Aug 13, 2019
CVE-2016-10869 on NVD →
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] < 4.0.6
unknown
[en] The contact-form-plugin plugin before 4.0.6 for WordPress has multiple XSS issues.
- Affected:
- up to 4.0.6
- Fixed in:
- 4.0.6
- Disclosed:
- Aug 13, 2019
CVE-2017-18491 on NVD →
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] < 3.52
unknown
[en] The contact-form-plugin plugin before 3.52 for WordPress has XSS.
- Affected:
- up to 3.52
- Fixed in:
- 3.52
- Disclosed:
- Aug 13, 2019
CVE-2013-7475 on NVD →
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] < 3.96
unknown
[en] The contact-form-plugin plugin before 3.96 for WordPress has XSS.
- Affected:
- up to 3.96
- Fixed in:
- 3.96
- Disclosed:
- Aug 13, 2019
CVE-2015-9295 on NVD →
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] < 4.0.2
unknown
[en] The contact-form-plugin plugin before 4.0.2 for WordPress has XSS.
- Affected:
- up to 4.0.2
- Fixed in:
- 4.0.2
- Disclosed:
- Aug 13, 2019
CVE-2016-10869 on NVD →
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] < 4.0.6
unknown
[en] Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,...
- Affected:
- up to 4.0.6
- Fixed in:
- 4.0.6
- Disclosed:
- May 22, 2017
CVE-2017-2171 on NVD →
Contact Form by BestWebSoft <= 3.95 - ReflectedCross-Site Scripting
medium
The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.95 due to insufficient input sanitization and output escaping on the 'category' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that ex...
- CVSS:
- 6.1
- Affected:
- up to 3.96
- Fixed in:
- 3.96
- Disclosed:
- Apr 12, 2017
CVE-2015-9295 on NVD →
Advanced Contact Us Form Builder for WordPress <= 4.0.5 - Reflected Cross-Site Scripting
medium
The Advanced Contact Us Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping on the 'category' parameter. This makes it possible for unauthenticated attackers to inject arbitrary...
- CVSS:
- 6.1
- Affected:
- up to 4.0.6
- Fixed in:
- 4.0.6
- Disclosed:
- Apr 12, 2017
CVE-2017-18491 on NVD →
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] < 3.82
unknown
This plugin is prone to a cross site scripting vulnerability in contact_form.php cntctfrm_contact_email parameter.
Update the plugin.
- Affected:
- up to 3.82
- Fixed in:
- 3.82
- Disclosed:
- Nov 27, 2015
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] < 3.83
unknown
This plugin is prone to an unauthorized language manipulation vulnerability.
Update the plugin.
- Affected:
- up to 3.83
- Fixed in:
- 3.83
- Disclosed:
- Nov 27, 2015
Contact Form <= 3.82 - Authorization Bypass
medium
The Contact Form plugin WordPress is vulnerable to authorization bypass in versions up to, and including, 3.82. This is due to missing capability checks and nonce validation on the add and remove language AJAX functions. This makes it possible for authenticated subscriber+ attackers to use the AJAX actions to manipulat...
- CVSS:
- 6.4
- Affected:
- up to 3.82
- Fixed in:
- 3.83
- Disclosed:
- Jan 22, 2015
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] < 3.83
unknown
The Contact Form plugin WordPress is vulnerable to authorization bypass in versions up to, and including, 3.82. This is due to missing capability checks and nonce validation on the add and remove language AJAX functions. This makes it possible for authenticated subscriber+ attackers to use the AJAX actions to manipulat...
- Affected:
- up to 3.83
- Fixed in:
- 3.83
- Disclosed:
- Jan 22, 2015
Contact Form Plugin <= 3.81 - Unauthenticated Stored Cross-Site Scripting
high
The Contact Form by BestWebSoft – Advanced Contact Us Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all versions up to, and including, 3.81 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated att...
- CVSS:
- 7.2
- Affected:
- up to 3.81
- Fixed in:
- 3.82
- Disclosed:
- Aug 7, 2014
CVE-2014-125095 on NVD →
Contact Form By BestWebSoft<= 3.34 - Cross-Site Scripting
medium
The Contact Form By BestWebSoft plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 3.34
- Fixed in:
- 3.35
- Disclosed:
- Aug 26, 2013
CVE-2013-7481 on NVD →
Contact Form by BestWebSoft <= 3.51 - Cross-Site Scripting
medium
The Contact Form by BestWebSoft plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 3.51 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser. CVE-2013-10022 may be a d...
- CVSS:
- 6.1
- Affected:
- up to 3.51
- Fixed in:
- 3.52
- Disclosed:
- Aug 13, 2013
CVE-2013-7475 on NVD →
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] < 3.82
unknown
The Contact Form by BestWebSoft WordPress plugin was affected by a contact_form.php cntctfrm_contact_email Parameter XSS security vulnerability.
- Affected:
- up to 3.82
- Fixed in:
- 3.82
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] < 3.82
unknown
The Contact Form by BestWebSoft WordPress plugin was affected by an Unauthorized Language Manipulation security vulnerability.
- Affected:
- up to 3.82
- Fixed in:
- 3.82
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress [contact-form-plugin] < 4.0.6
unknown
- Affected:
- up to 4.0.6
- Fixed in:
- 4.0.6
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database