plugin

Contact Forms Vulnerabilities

23 known security issues reported for the Contact Forms WordPress plugin. Most recent disclosed Jun 2, 2025.

2 high 9 medium

Running Contact Forms on your site? Check whether your installed version is affected.

Scan your site free

Contact Forms by Cimatti Plugin <= 1.9.8 - Cross-Site Request Forgery

medium

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.8. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can...

CVSS:
4.3
Affected:
up to 1.9.8
Fixed in:
1.9.9
Disclosed:
Jun 2, 2025

CVE-2025-49069 on NVD →

WordPress Contact Forms by Cimatti [contact-forms] < 1.9.9

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Cimatti Consulting Contact Forms by Cimatti allows Cross Site Request Forgery.This issue affects Contact Forms by Cimatti: from n/a through 1.9.8.

Affected:
up to 1.9.9
Fixed in:
1.9.9
Disclosed:
Jun 2, 2025

CVE-2025-49069 on NVD →

WordPress Contact Forms by Cimatti [contact-forms] < 1.9.5

unknown

[en] The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the accua_forms_download_submitted_file() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to download other user s...

Affected:
up to 1.9.5
Fixed in:
1.9.5
Disclosed:
Feb 1, 2025

CVE-2024-12184 on NVD →

WordPress Contact Forms by Cimatti <= 1.9.4 - Missing Authorization to Unauthenticated Form Submission Download

medium

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the accua_forms_download_submitted_file() function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to download other user submit...

CVSS:
5.3
Affected:
up to 1.9.4
Fixed in:
1.9.5
Disclosed:
Jan 31, 2025

CVE-2024-12184 on NVD →

WordPress Contact Forms by Cimatti [contact-forms] < 1.5.8

unknown

[en] Missing Authorization vulnerability in Cimatti Consulting Contact Forms by Cimatti allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Forms by Cimatti: from n/a through 1.5.7.

Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
Dec 13, 2024

CVE-2023-35051 on NVD →

WordPress Contact Forms by Cimatti [contact-forms] < 1.9.3

unknown

[en] The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.2. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to delete forms via a f...

Affected:
up to 1.9.3
Fixed in:
1.9.3
Disclosed:
Nov 27, 2024

CVE-2024-10521 on NVD →

WordPress Contact Forms by Cimatti <= 1.9.2 - Cross-Site Request Forgery via process_bulk_action Function

medium

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.2. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to delete forms via a forged...

CVSS:
4.3
Affected:
up to 1.9.2
Fixed in:
1.9.3
Disclosed:
Nov 26, 2024

CVE-2024-10521 on NVD →

WordPress Contact Forms by Cimatti [contact-forms] < 1.9.1

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cimatti Consulting Contact Forms by Cimatti allows Stored XSS.This issue affects Contact Forms by Cimatti: from n/a through 1.8.0.

Affected:
up to 1.9.1
Fixed in:
1.9.1
Disclosed:
Mar 31, 2024

CVE-2024-30549 on NVD →

Contact Forms by Cimatti <= 1.8.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and...

CVSS:
4.4
Affected:
up to 1.8.0
Fixed in:
1.9.1
Disclosed:
Mar 29, 2024

CVE-2024-30549 on NVD →

WordPress Contact Forms by Cimatti [contact-forms] < 1.8.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cimatti Consulting Contact Forms by Cimatti allows Stored XSS.This issue affects Contact Forms by Cimatti: from n/a through 1.7.0.

Affected:
up to 1.8.0
Fixed in:
1.8.0
Disclosed:
Mar 19, 2024

CVE-2024-29117 on NVD →

Contact Forms by Cimatti <= 1.7.0 - Unauthenticated Stored Cross-Site Scripting

high

The Contact Forms by Cimatti plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.7.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a us...

CVSS:
7.2
Affected:
up to 1.7.0
Fixed in:
1.8.0
Disclosed:
Mar 16, 2024

CVE-2024-29117 on NVD →

WordPress Contact Forms by Cimatti [contact-forms] < 1.6.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.6.0 versions.

Affected:
up to 1.6.1
Fixed in:
1.6.1
Disclosed:
Nov 13, 2023

CVE-2023-47230 on NVD →

Contact Forms by Cimatti <= 1.6.0 - Cross-Site Request Forgery via accua_forms_list_page_table

medium

The Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.0. This is due to missing or incorrect nonce validation on the accua_forms_list_page_table function. This makes it possible for unauthenticated attackers to trash posts via a forged reques...

CVSS:
4.3
Affected:
up to 1.6.0
Fixed in:
1.6.1
Disclosed:
Oct 25, 2023

CVE-2023-47230 on NVD →

WordPress Contact Forms by Cimatti <= 1.5.7 - Missing Authorization

medium

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.5.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.5.7
Fixed in:
1.5.8
Disclosed:
Jun 13, 2023

CVE-2023-35051 on NVD →

WordPress Contact Forms by Cimatti [contact-forms] < 1.5.8

unknown

[en] The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms c...

Affected:
up to 1.5.8
Fixed in:
1.5.8
Disclosed:
Jun 13, 2023

CVE-2023-2563 on NVD →

WordPress Contact Forms by Cimatti <= 1.5.7 - Cross-Site Request Forgery via _accua_forms_form_edit_action

medium

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.7. This is due to missing or incorrect nonce validation on the function _accua_forms_form_edit_action. This makes it possible for unauthenticated attackers to delete forms create...

CVSS:
4.3
Affected:
up to 1.5.7
Fixed in:
1.5.8
Disclosed:
Jun 12, 2023

CVE-2023-2563 on NVD →

WordPress Contact Forms by Cimatti [contact-forms] < 1.5.5

unknown

[en] Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions.

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Apr 7, 2023

CVE-2023-28781 on NVD →

WordPress Contact Forms by Cimatti [contact-forms] < 1.5.5

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cimatti Consulting WordPress Contact Forms by Cimatti plugin <= 1.5.4 versions.

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Apr 7, 2023

CVE-2023-28789 on NVD →

WordPress Contact Forms by Cimatti <= 1.5.4 - Unauthenticated Stored Cross-Site Scripting

high

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form parameters in versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

CVSS:
7.2
Affected:
up to 1.5.4
Fixed in:
1.5.5
Disclosed:
Mar 27, 2023

CVE-2023-28781 on NVD →

Contact Forms by Cimatti <= 1.5.4 - Reflected Cross-Site Scripting via 'form-field-id', 'edit-fid', 'id', 'name', 'type', 'description' Parameters

medium

The Contact Forms by Cimatti plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'form-field-id', 'edit-fid', 'id', 'name', 'type', 'description' parameter in versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthentica...

CVSS:
6.1
Affected:
up to 1.5.4
Fixed in:
1.5.5
Disclosed:
Mar 27, 2023

CVE-2023-28789 on NVD →

WordPress Contact Forms by Cimatti [contact-forms] < 1.5.5

unknown

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form parameters in versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

Affected:
up to 1.5.5
Fixed in:
1.5.5
Disclosed:
Mar 27, 2023

WordPress Contact Forms by Cimatti [contact-forms] < 1.4.12

unknown

[en] The WordPress Contact Forms by Cimatti WordPress plugin before 1.4.12 does not sanitise and escape the Form Title before outputting it in some admin pages. which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

Affected:
up to 1.4.12
Fixed in:
1.4.12
Disclosed:
Oct 25, 2021

CVE-2021-24744 on NVD →

Cimatti Contact Forms <= 1.4.11 - Cross-Site Scripting

medium

The Cimatti Contact Forms plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.4.11.This is due to insufficient input sanitization and output escaping on the title value of a form and makes it possible for attackers to inject arbitrary web scripts that execute in a victim's bro...

CVSS:
5.5
Affected:
up to 1.4.12
Fixed in:
1.4.12
Disclosed:
Sep 27, 2021

CVE-2021-24744 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database