Lead Form Builder & Contact Form <= 2.0.1 - Unauthenticated Stored Cross-Site Scripting
high
The Lead Form Builder & Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...
- CVSS:
- 7.2
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- Mar 23, 2026
CVE-2026-32532 on NVD →
Contact Form & Lead Form Elementor Builder - Unauthenticated Stored Cross-Site Scripting vulnerability
high
Unauthenticated Stored Cross-Site Scripting vulnerability
- CVSS:
- 7.1
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- Mar 12, 2026
Responsive Contact Form Builder & Lead Generation Plugin <= 2.0.1 - Unauthenticated Stored Cross-Site Scripting
high
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 via form field submissions. This is due to insufficient input sanitization in the lfb_lead_sanitize() function which omits certain field types from i...
- CVSS:
- 7.2
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- Mar 10, 2026
CVE-2026-1454 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin [lead-form-builder] <= 2.0.1 (unfixed)
unknown
[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder lead-form-builder allows Retrieve Embedded Sensitive Data.This issue affects Contact Form & Lead Form Elementor Builder: from n/a through <= 2.0.1.
- Affected:
- up to 2.0.1
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-68046 on NVD →
Contact Form & Lead Form Elementor Builder <= 2.0.1 - Authenticated (Subscriber+) Information Exposure
medium
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 2.0.1
- Fixed in:
- 2.0.2
- Disclosed:
- Jan 20, 2026
CVE-2025-68046 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin [lead-form-builder] < 1.9.8
unknown
[en] The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin before 1.9.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in mu...
- Affected:
- up to 1.9.8
- Fixed in:
- 1.9.8
- Disclosed:
- May 15, 2025
CVE-2024-10475 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin <= 1.9.7 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator...
- CVSS:
- 4.4
- Affected:
- up to 1.9.7
- Fixed in:
- 1.9.8
- Disclosed:
- Mar 3, 2025
CVE-2024-10475 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin [lead-form-builder] < 1.9.2
unknown
[en] The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This mak...
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.2
- Disclosed:
- May 22, 2024
CVE-2024-4261 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin <= 1.9.1 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
medium
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it...
- CVSS:
- 5.4
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.2
- Disclosed:
- May 21, 2024
CVE-2024-4261 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin [lead-form-builder] < 1.9.8
unknown
[en] The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin through 1.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in m...
- Affected:
- up to 1.9.8
- Fixed in:
- 1.9.8
- Disclosed:
- May 3, 2024
CVE-2024-3637 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin [lead-form-builder] < 1.9.0
unknown
[en] The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.9. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those...
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.0
- Disclosed:
- May 2, 2024
CVE-2024-1415 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin [lead-form-builder] < 1.9.0
unknown
[en] The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on several functions in all versions up to, and including, 1.8.9. This makes it possible for unauthenticated attackers to invoke those functions.
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.0
- Disclosed:
- May 2, 2024
CVE-2024-1416 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin <= 1.9.7 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator...
- CVSS:
- 6.6
- Affected:
- up to 1.9.7
- Fixed in:
- 1.9.8
- Disclosed:
- Apr 12, 2024
CVE-2024-3637 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Missing Authorization
medium
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on several functions in all versions up to, and including, 1.8.9. This makes it possible for unauthenticated attackers to invoke those functions.
- CVSS:
- 4.3
- Affected:
- up to 1.8.9
- Fixed in:
- 1.9.0
- Disclosed:
- Apr 11, 2024
CVE-2024-1416 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Cross-Site Request Forgery
medium
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.9. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to invoke those funct...
- CVSS:
- 4.3
- Affected:
- up to 1.8.9
- Fixed in:
- 1.9.0
- Disclosed:
- Apr 11, 2024
CVE-2024-1415 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin [lead-form-builder] < 1.7.0
unknown
[en] The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
- Disclosed:
- Jan 16, 2024
CVE-2022-23179 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin [lead-form-builder] < 1.7.4
unknown
[en] The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- Jan 16, 2024
CVE-2022-23180 on NVD →
Multiple Plugins By ThemeHunk (Various Versions) - Missing Authorization via settings_init
medium
Multiple Plugins By ThemeHunk are vulnerable to unauthorized plugin setting modification due to a missing capability check on the settings_init function in various versions. This makes it possible for unauthenticated attackers to reset plugin settings.
- CVSS:
- 6.5
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.5
- Disclosed:
- Mar 22, 2023
CVE-2023-25969 on NVD →
Contact Form & Lead Form Elementor Builder < 1.7.4 - Arbitrary Settings Change
medium
The Contact Form & Lead Form Elementor Builder plugin for WordPress is vulnerable to Arbitrary Settings Change in versions before 1.7.4. This is due to missing capabilities checks on several functions. This makes it possible for authenticated attackers with subscriber-level privileges or above to arbitrarily change plu...
- CVSS:
- 6.3
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- Feb 1, 2022
CVE-2022-23180 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin < 1.7.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to 1.7.0 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-lev...
- CVSS:
- 4.4
- Affected:
- up to 1.7.0
- Fixed in:
- 1.7.0
- Disclosed:
- Jan 5, 2022
CVE-2022-23179 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin [lead-form-builder] < 1.6.4
unknown
[en] The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted Leads
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.4
- Disclosed:
- Dec 27, 2021
CVE-2021-24967 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin [lead-form-builder] < 1.6.8
unknown
Arbitrary Lead Deletion vulnerability discovered by WPScanTeam in WordPress Contact Form & Lead Form Elementor Builder plugin (versions <= 1.6.7).
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.8
- Disclosed:
- Dec 22, 2021
Contact Form & Lead Form Elementor Builder <= 1.6.3 - Unauthenticated Stored Cross-Site Scripting
high
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted Leads
- CVSS:
- 7.2
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.4
- Disclosed:
- Nov 29, 2021
CVE-2021-24967 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin [lead-form-builder] < 1.8.5
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.5
CVE-2023-25969 on NVD →
Responsive Contact Form Builder & Lead Generation Plugin [lead-form-builder] < 1.6.8
unknown
The plugin does not have capability and CSRF checks in the delete_leads_backend AJAX action, available to any authenticated users. As a result, users with a role as low as subscriber could delete arbitrary Leads. Attackers could also make any logged in users delete leads via a CSRF attack
- Affected:
- up to 1.6.8
- Fixed in:
- 1.6.8
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database