Simple Basic Contact Form <= 20250114 - Unauthenticated Stored Cross-Site Scripting
high
The Simple Basic Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 20250114 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever...
- CVSS:
- 7.2
- Affected:
- up to 20250114
- Fix:
- No patched version reported
- Disclosed:
- Jun 25, 2026
CVE-2026-8172 on NVD →
Simple Basic Contact Form [simple-basic-contact-form] < 20250114
unknown
[en] The Simple Basic Contact Form WordPress plugin before 20250114 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 20250114
- Fixed in:
- 20250114
- Disclosed:
- May 15, 2025
CVE-2024-12716 on NVD →
Simple Basic Contact Form <= 20240511 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Simple Basic Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 20240511 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...
- CVSS:
- 4.4
- Affected:
- up to 20240511
- Fixed in:
- 20250114
- Disclosed:
- Mar 3, 2025
CVE-2024-12716 on NVD →
Simple Basic Contact Form [simple-basic-contact-form] < 20240511
unknown
[en] The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 20240502. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on the functionality of other plugins instal...
- Affected:
- up to 20240511
- Fixed in:
- 20240511
- Disclosed:
- May 14, 2024
CVE-2024-4144 on NVD →
Simple Basic Contact Form <= 20240502 - Unauthenticated Arbitrary Shortcode Execution
medium
The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 20240502. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on the functionality of other plugins installed i...
- CVSS:
- 6.5
- Affected:
- up to 20240502
- Fixed in:
- 20240511
- Disclosed:
- May 13, 2024
CVE-2024-4144 on NVD →
Simple Basic Contact Form [simple-basic-contact-form] < 20240502
unknown
[en] The Simple Basic Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘scf_email’ parameter in versions up to, and including, 20221201 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...
- Affected:
- up to 20240502
- Fixed in:
- 20240502
- Disclosed:
- May 9, 2024
CVE-2024-4150 on NVD →
Simple Basic Contact Form <= 20221201 - Reflected Cross-Site Scripting
medium
The Simple Basic Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘scf_email’ parameter in versions up to, and including, 20221201 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- up to 20221201
- Fixed in:
- 20240502
- Disclosed:
- May 3, 2024
CVE-2024-4150 on NVD →
Simple Basic Contact Form [simple-basic-contact-form] < 20221201
unknown
[en] The Simple Basic Contact Form WordPress plugin before 20221201 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 20221201
- Fixed in:
- 20221201
- Disclosed:
- Dec 26, 2022
CVE-2022-4226 on NVD →
Simple Basic Contact Form <= 20220207 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Simple Basic Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its settings parameters in versions up to, and including, 20220207 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permi...
- CVSS:
- 5.5
- Affected:
- up to 20220207
- Fixed in:
- 20221201
- Disclosed:
- Dec 2, 2022
CVE-2022-4226 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database