plugin

Formcraft Vulnerabilities

8 known security issues reported for the Formcraft WordPress plugin. Most recent disclosed Jul 27, 2026.

2 critical 1 high

Running Formcraft on your site? Check whether your installed version is affected.

Scan your site free

FormCraft <= 3.9.15 - Unauthenticated Server-Side Request Forgery

high

The FormCraft plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.9.15. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal...

CVSS:
7.2
Affected:
up to 3.9.15
Fixed in:
3.9.16
Disclosed:
Jul 27, 2026

CVE-2026-65442 on NVD →

FormCraft Basic [formcraft] < 1.0.6

unknown

[en] The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php.

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Aug 23, 2017

CVE-2017-13137 on NVD →

FormCraft Basic [formcraft] < 2.0.6

unknown

This plugin is prone to an arbitrary file deletion vulnerability. Update the plugin.

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
May 15, 2015

Formcraft (Unknown Versions) - Arbitrary File Deletion

critical

The formcraft plugin for WordPress is vulnerable to Arbitrary File Deletion via the 'function.php' file. This makes it possible for unauthenticated attackers to delete files within the scope of the vulnerable service.

CVSS:
9.1
Affected:
up to 2.0.5
Fix:
No patched version reported
Disclosed:
Sep 17, 2014

FormCraft Basic [formcraft] <= 2.0.5 (unfixed)

unknown

The formcraft plugin for WordPress is vulnerable to Arbitrary File Deletion via the 'function.php' file. This makes it possible for unauthenticated attackers to delete files within the scope of the vulnerable service.

Affected:
up to 2.0.5
Fix:
No patched version reported
Disclosed:
Sep 17, 2014

FormCraft Basic [formcraft] < 1.3.8

unknown

[en] SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

Affected:
up to 1.3.8
Fixed in:
1.3.8
Disclosed:
Dec 20, 2013

CVE-2013-7187 on NVD →

FormCraft <= 1.3.7 - SQL Injection

critical

SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS:
9.8
Affected:
up to 1.3.7
Fixed in:
1.3.8
Disclosed:
Dec 8, 2013

CVE-2013-7187 on NVD →

FormCraft Basic [formcraft] <= 2.0.5 (unfixed)

unknown

Successfully tested with v2.0.2

Affected:
up to 2.0.5
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database