plugin

Simple Basic Contact Form Vulnerabilities

9 known security issues reported for the Simple Basic Contact Form WordPress plugin. Most recent disclosed Jun 25, 2026.

1 high 4 medium

Running Simple Basic Contact Form on your site? Check whether your installed version is affected.

Scan your site free

Simple Basic Contact Form <= 20250114 - Unauthenticated Stored Cross-Site Scripting

high

The Simple Basic Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 20250114 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever...

CVSS:
7.2
Affected:
up to 20250114
Fix:
No patched version reported
Disclosed:
Jun 25, 2026

CVE-2026-8172 on NVD →

Simple Basic Contact Form [simple-basic-contact-form] < 20250114

unknown

[en] The Simple Basic Contact Form WordPress plugin before 20250114 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 20250114
Fixed in:
20250114
Disclosed:
May 15, 2025

CVE-2024-12716 on NVD →

Simple Basic Contact Form <= 20240511 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Simple Basic Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 20240511 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...

CVSS:
4.4
Affected:
up to 20240511
Fixed in:
20250114
Disclosed:
Mar 3, 2025

CVE-2024-12716 on NVD →

Simple Basic Contact Form [simple-basic-contact-form] < 20240511

unknown

[en] The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 20240502. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on the functionality of other plugins instal...

Affected:
up to 20240511
Fixed in:
20240511
Disclosed:
May 14, 2024

CVE-2024-4144 on NVD →

Simple Basic Contact Form <= 20240502 - Unauthenticated Arbitrary Shortcode Execution

medium

The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 20240502. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on the functionality of other plugins installed i...

CVSS:
6.5
Affected:
up to 20240502
Fixed in:
20240511
Disclosed:
May 13, 2024

CVE-2024-4144 on NVD →

Simple Basic Contact Form [simple-basic-contact-form] < 20240502

unknown

[en] The Simple Basic Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘scf_email’ parameter in versions up to, and including, 20221201 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...

Affected:
up to 20240502
Fixed in:
20240502
Disclosed:
May 9, 2024

CVE-2024-4150 on NVD →

Simple Basic Contact Form <= 20221201 - Reflected Cross-Site Scripting

medium

The Simple Basic Contact Form plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘scf_email’ parameter in versions up to, and including, 20221201 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
6.1
Affected:
up to 20221201
Fixed in:
20240502
Disclosed:
May 3, 2024

CVE-2024-4150 on NVD →

Simple Basic Contact Form [simple-basic-contact-form] < 20221201

unknown

[en] The Simple Basic Contact Form WordPress plugin before 20221201 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 20221201
Fixed in:
20221201
Disclosed:
Dec 26, 2022

CVE-2022-4226 on NVD →

Simple Basic Contact Form <= 20220207 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Simple Basic Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its settings parameters in versions up to, and including, 20220207 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permi...

CVSS:
5.5
Affected:
up to 20220207
Fixed in:
20221201
Disclosed:
Dec 2, 2022

CVE-2022-4226 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database