plugin

Crm Perks Forms Vulnerabilities

17 known security issues reported for the Crm Perks Forms WordPress plugin. Most recent disclosed Jul 8, 2026.

2 critical 1 high 6 medium

Running Crm Perks Forms on your site? Check whether your installed version is affected.

Scan your site free

CRM Perks Forms <= 1.1.7 - Reflected Cross-Site Scripting

medium

The CRM Perks Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully...

CVSS:
6.1
Affected:
up to 1.1.7
Fixed in:
1.1.8
Disclosed:
Jul 8, 2026

CVE-2026-57421 on NVD →

CRM Perks Forms &#8211; WordPress Form Builder [crm-perks-forms] < 1.1.6

unknown

[en] Missing Authorization vulnerability in CRM Perks CRM Perks Forms allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CRM Perks Forms: from n/a through 1.1.5.

Affected:
up to 1.1.6
Fixed in:
1.1.6
Disclosed:
Nov 1, 2024

CVE-2024-37463 on NVD →

CRM Perks Forms &#8211; WordPress Form Builder [crm-perks-forms] < 1.1.4

unknown

[en] The CRM Perks Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'handle_uploaded_files' function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrar...

Affected:
up to 1.1.4
Fixed in:
1.1.4
Disclosed:
Aug 6, 2024

CVE-2024-7484 on NVD →

CRM Perks Forms <= 1.1.3 - Authenticated (Administrator+) Arbitrary File Upload

high

The CRM Perks Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'handle_uploaded_files' function in versions up to, and including, 1.1.3. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary fil...

CVSS:
7.2
Affected:
up to 1.1.3
Fixed in:
1.1.4
Disclosed:
Aug 5, 2024

CVE-2024-7484 on NVD →

CRM Perks Forms <= 1.1.5 - Missing Authorization to Unauthenticated Form Submission

medium

The CRM Perks Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the post_form() function in versions up to, and including, 1.1.5. This makes it possible for unauthenticated attackers to submit forms that should be restricted to authenticated users.

CVSS:
5.3
Affected:
up to 1.1.5
Fixed in:
1.1.6
Disclosed:
Jul 1, 2024

CVE-2024-37463 on NVD →

CRM Perks Forms &#8211; WordPress Form Builder [crm-perks-forms] < 1.1.5

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms allows Stored XSS.This issue affects CRM Perks Forms: from n/a through 1.1.4.

Affected:
up to 1.1.5
Fixed in:
1.1.5
Disclosed:
Mar 29, 2024

CVE-2024-30446 on NVD →

CRM Perks Forms &#8211; WordPress Form Builder [crm-perks-forms] < 1.1.5

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4.

Affected:
up to 1.1.5
Fixed in:
1.1.5
Disclosed:
Mar 29, 2024

CVE-2024-30498 on NVD →

CRM Perks Forms &#8211; WordPress Form Builder [crm-perks-forms] < 1.1.5

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through 1.1.4.

Affected:
up to 1.1.5
Fixed in:
1.1.5
Disclosed:
Mar 29, 2024

CVE-2024-30499 on NVD →

CRM Perks Forms <= 1.1.4 - Unauthenticated SQL Injection

critical

The CRM Perks Forms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries...

CVSS:
10
Affected:
up to 1.1.4
Fixed in:
1.1.5
Disclosed:
Mar 28, 2024

CVE-2024-30498 on NVD →

CRM Perks Forms <= 1.1.4 - Authenticated (Contributor+) SQL Injection

critical

The CRM Perks Forms plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and...

CVSS:
9.9
Affected:
up to 1.1.4
Fixed in:
1.1.5
Disclosed:
Mar 28, 2024

CVE-2024-30499 on NVD →

CRM Perks Forms <= 1.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 1.1.4
Fixed in:
1.1.5
Disclosed:
Mar 28, 2024

CVE-2024-30446 on NVD →

CRM Perks Forms &#8211; WordPress Form Builder [crm-perks-forms] < 1.1.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms – WordPress Form Builder allows Stored XSS.This issue affects CRM Perks Forms – WordPress Form Builder: from n/a through 1.1.2.

Affected:
up to 1.1.3
Fixed in:
1.1.3
Disclosed:
Feb 1, 2024

CVE-2023-51536 on NVD →

CRM Perks Forms <= 1.1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The CRM Perks Forms – WordPress Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping on the label field. This makes it possible for authenticated attackers, with administra...

CVSS:
4.4
Affected:
up to 1.1.2
Fixed in:
1.1.3
Disclosed:
Dec 27, 2023

CVE-2023-51536 on NVD →

CRM Perks Forms &#8211; WordPress Form Builder [crm-perks-forms] < 1.1.2

unknown

[en] The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject a...

Affected:
up to 1.1.2
Fixed in:
1.1.2
Disclosed:
May 31, 2023

CVE-2023-2836 on NVD →

CRM Perks Forms <= 1.1.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The CRM Perks Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form settings in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitr...

CVSS:
4.4
Affected:
up to 1.1.1
Fixed in:
1.1.2
Disclosed:
May 30, 2023

CVE-2023-2836 on NVD →

CRM Perks Forms &#8211; WordPress Form Builder [crm-perks-forms] < 1.1.1

unknown

[en] Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.

Affected:
up to 1.1.1
Fixed in:
1.1.1
Disclosed:
Jan 14, 2023

CVE-2022-38467 on NVD →

CRM Perks Forms <= 1.1.0 - Reflected Cross-Site Scripting

medium

The CRM Perks Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.10 due to insufficient input sanitization and output escaping in the ~/templates/sample_file.php file. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

CVSS:
6.1
Affected:
up to 1.1.0
Fixed in:
1.1.1
Disclosed:
Sep 30, 2022

CVE-2022-38467 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database