HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion
medium
The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.26.12 via the happyforms_get_form_partial() function. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.6
- Affected:
- up to 1.26.12
- Fixed in:
- 1.26.13
- Disclosed:
- Jul 9, 2026
CVE-2025-11977 on NVD →
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms <= 1.26.13 - Unauthenticated PHP Object Injection
high
The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.26.13 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP...
- CVSS:
- 8.1
- Affected:
- up to 1.26.13
- Fixed in:
- 1.26.14
- Disclosed:
- Jun 4, 2026
CVE-2026-49768 on NVD →
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms [happyforms] < 1.26.3
unknown
[en] The Happyforms WordPress plugin before 1.26.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 1.26.3
- Fixed in:
- 1.26.3
- Disclosed:
- May 15, 2025
CVE-2024-10054 on NVD →
Happyforms <= 1.26.2 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.26.2 due to insufficient input sanitization and output escaping. This makes it possi...
- CVSS:
- 4.4
- Affected:
- up to 1.26.2
- Fixed in:
- 1.26.3
- Disclosed:
- Nov 20, 2024
CVE-2024-10054 on NVD →
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms [happyforms] < 1.26.1
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Happyforms allows Stored XSS.This issue affects Happyforms: from n/a through 1.26.0.
- Affected:
- up to 1.26.1
- Fixed in:
- 1.26.1
- Disclosed:
- Sep 15, 2024
CVE-2024-44063 on NVD →
Happyforms <= 1.26.0 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Happyforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.26.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will...
- CVSS:
- 6.4
- Affected:
- up to 1.26.0
- Fixed in:
- 1.26.1
- Disclosed:
- Aug 29, 2024
CVE-2024-44063 on NVD →
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms [happyforms] < 1.25.11
unknown
[en] Missing Authorization vulnerability in Happyforms.This issue affects Happyforms: from n/a through 1.25.10.
- Affected:
- up to 1.25.11
- Fixed in:
- 1.25.11
- Disclosed:
- Jun 11, 2024
CVE-2024-23521 on NVD →
Happyforms <= 1.25.10 - Missing Authorization
medium
The Happyforms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in all versions up to, and including, 1.25.10. This makes it possible for unauthenticated attackers to perform unauthorized actions.
- CVSS:
- 5.3
- Affected:
- up to 1.25.10
- Fixed in:
- 1.25.11
- Disclosed:
- Jan 31, 2024
CVE-2024-23521 on NVD →
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms [happyforms] < 1.25.10
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Happyforms Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms allows Reflected XSS.This issue affects Form builder to get in touch with visitors, grow your email lis...
- Affected:
- up to 1.25.10
- Fixed in:
- 1.25.10
- Disclosed:
- Nov 30, 2023
CVE-2023-48752 on NVD →
Happyforms <= 1.25.9 - Reflected Cross-Site Scripting
medium
The Form builder to get in touch with visitors, grow your email list and collect payments — Happyforms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.25.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated...
- CVSS:
- 6.1
- Affected:
- up to 1.25.9
- Fixed in:
- 1.25.10
- Disclosed:
- Nov 27, 2023
CVE-2023-48752 on NVD →
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms [happyforms] < 1.22.0
unknown
[en] The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected:
- up to 1.22.0
- Fixed in:
- 1.22.0
- Disclosed:
- Feb 6, 2023
CVE-2023-0096 on NVD →
Happyforms <= 1.21.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Blocks
medium
The Happyforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ and 'anchor' block options in versions up to, and including, 1.21.1 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in p...
- CVSS:
- 6.4
- Affected:
- up to 1.21.1
- Fixed in:
- 1.22.0
- Disclosed:
- Jan 13, 2023
CVE-2023-0096 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database