FormCraft <= 3.9.15 - Unauthenticated Server-Side Request Forgery
high
The FormCraft plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.9.15. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from internal...
- CVSS:
- 7.2
- Affected:
- up to 3.9.15
- Fixed in:
- 3.9.16
- Disclosed:
- Jul 27, 2026
CVE-2026-65442 on NVD →
FormCraft Basic [formcraft] < 1.0.6
unknown
[en] The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Aug 23, 2017
CVE-2017-13137 on NVD →
FormCraft Basic [formcraft] < 2.0.6
unknown
This plugin is prone to an arbitrary file deletion vulnerability.
Update the plugin.
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- May 15, 2015
Formcraft (Unknown Versions) - Arbitrary File Deletion
critical
The formcraft plugin for WordPress is vulnerable to Arbitrary File Deletion via the 'function.php' file. This makes it possible for unauthenticated attackers to delete files within the scope of the vulnerable service.
- CVSS:
- 9.1
- Affected:
- up to 2.0.5
- Fix:
- No patched version reported
- Disclosed:
- Sep 17, 2014
FormCraft Basic [formcraft] <= 2.0.5 (unfixed)
unknown
The formcraft plugin for WordPress is vulnerable to Arbitrary File Deletion via the 'function.php' file. This makes it possible for unauthenticated attackers to delete files within the scope of the vulnerable service.
- Affected:
- up to 2.0.5
- Fix:
- No patched version reported
- Disclosed:
- Sep 17, 2014
FormCraft Basic [formcraft] < 1.3.8
unknown
[en] SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
- Affected:
- up to 1.3.8
- Fixed in:
- 1.3.8
- Disclosed:
- Dec 20, 2013
CVE-2013-7187 on NVD →
FormCraft <= 1.3.7 - SQL Injection
critical
SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.8
- Disclosed:
- Dec 8, 2013
CVE-2013-7187 on NVD →
FormCraft Basic [formcraft] <= 2.0.5 (unfixed)
unknown
Successfully tested with v2.0.2
- Affected:
- up to 2.0.5
- Fix:
- No patched version reported
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database