plugin

Ultimate Form Builder Lite Vulnerabilities

13 known security issues reported for the Ultimate Form Builder Lite WordPress plugin. Most recent disclosed Feb 21, 2022.

1 critical 2 medium

Running Ultimate Form Builder Lite on your site? Check whether your installed version is affected.

Scan your site free

Contact Form for WordPress &#8211; Ultimate Form Builder Lite [ultimate-form-builder-lite] < 1.5.1 (closed)

unknown

[en] Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confus...

Affected:
up to 1.5.1
Fixed in:
1.5.1
Disclosed:
Feb 21, 2022

CVE-2021-24867 on NVD →

Ultimate Form Builder Lite <= 1.3.7 - Cross-Site Scripting

medium

The Ultimate Form Builder Lite plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping on the 'form_id' parameter. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser...

CVSS:
6.4
Affected:
up to 1.3.7
Fixed in:
1.3.8
Disclosed:
Jun 20, 2018

Contact Form for WordPress &#8211; Ultimate Form Builder Lite [ultimate-form-builder-lite] < 1.3.8 (closed)

unknown

Authenticated Cross-Site Scripting (XSS) vulnerability found by Neven Biruski in WordPress Ultimate Form Builder Lite plugin (versions <= 1.3.7).

Affected:
up to 1.3.8
Fixed in:
1.3.8
Disclosed:
Jun 20, 2018

Contact Form for WordPress &#8211; Ultimate Form Builder Lite [ultimate-form-builder-lite] < 1.3.8 (closed)

unknown

SQL Injection (SQLi) vulnerability found by Neven Biruski in WordPress Ultimate Form Builder Lite plugin (versions <= 1.3.7).

Affected:
up to 1.3.8
Fixed in:
1.3.8
Disclosed:
Jun 20, 2018

Contact Form for WordPress &#8211; Ultimate Form Builder Lite [ultimate-form-builder-lite] < 1.3.8 (closed)

unknown

The Ultimate Form Builder Lite plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping on the 'form_id' parameter. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser...

Affected:
up to 1.3.8
Fixed in:
1.3.8
Disclosed:
Jun 20, 2018

Contact Form for WordPress &#8211; Ultimate Form Builder Lite [ultimate-form-builder-lite] < 1.3.7 (closed)

unknown

[en] The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php.

Affected:
up to 1.3.7
Fixed in:
1.3.7
Disclosed:
Oct 26, 2017

CVE-2017-15919 on NVD →

Contact Form for WordPress &#8211; Ultimate Form Builder Lite [ultimate-form-builder-lite] < 1.3.7 (closed)

unknown

SQL Injection vulnerability found by WordFence Security Team in Contact Form for WordPress – Ultimate Form Builder Lite plugin.

Affected:
up to 1.3.7
Fixed in:
1.3.7
Disclosed:
Oct 24, 2017

Ultimate Form Builder Lite <= 1.3.6 - SQL Injection to PHP Object Injection

critical

The ultimate-form-builder-lite plugin before 1.3.7 for WordPress has SQL Injection, with resultant PHP Object Injection, via wp-admin/admin-ajax.php.

CVSS:
9.8
Affected:
up to 1.3.7
Fixed in:
1.3.7
Disclosed:
Oct 23, 2017

CVE-2017-15919 on NVD →

Contact Form for WordPress &#8211; Ultimate Form Builder Lite [ultimate-form-builder-lite] < 1.3.3 (closed)

unknown

Contact Form for WordPress – Ultimate Form Builder Lite 1.3.2 WordPress plugin and earlier its versions suffers from Authenticated Cross-Site Scripting (XSS) vulnerability. Patched version (1.3.3) already available. Update plugin to the latest available version (at least 1.3.3).

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Apr 20, 2017

Ultimate Form Builder Lite <= 1.3.2 - Reflected Cross-Site Scripting

medium

The ultimate-form-builder-lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ufbl_form_id’ parameter in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
6.1
Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Apr 19, 2017

Contact Form for WordPress &#8211; Ultimate Form Builder Lite [ultimate-form-builder-lite] < 1.3.3 (closed)

unknown

The ultimate-form-builder-lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ufbl_form_id’ parameter in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Apr 19, 2017

Contact Form for WordPress &#8211; Ultimate Form Builder Lite [ultimate-form-builder-lite] < 1.3.8 (closed)

unknown

Authenticated XSS &amp; SQL Injection.

Affected:
up to 1.3.8
Fixed in:
1.3.8

Contact Form for WordPress &#8211; Ultimate Form Builder Lite [ultimate-form-builder-lite] < 1.3.3 (closed)

unknown
Affected:
up to 1.3.3
Fixed in:
1.3.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database