plugin

Very Simple Contact Form Vulnerabilities

8 known security issues reported for the Very Simple Contact Form WordPress plugin. Most recent disclosed Dec 13, 2024.

1 high 3 medium

Running Very Simple Contact Form on your site? Check whether your installed version is affected.

Scan your site free

VS Contact Form [very-simple-contact-form] < 14.0

unknown

[en] Weak Authentication vulnerability in Guido VS Contact Form allows Authentication Abuse.This issue affects VS Contact Form: from n/a through 14.0.

Affected:
up to 14.0
Fixed in:
14.0
Disclosed:
Dec 13, 2024

CVE-2023-41862 on NVD →

VS Contact Form [very-simple-contact-form] < 14.8

unknown

[en] Guessable CAPTCHA vulnerability in Guido VS Contact Form allows Functionality Bypass.This issue affects VS Contact Form: from n/a through 14.7.

Affected:
up to 14.8
Fixed in:
14.8
Disclosed:
May 17, 2024

CVE-2024-30540 on NVD →

VS Contact Form <= 14.7 - CAPTCHA Bypass

medium

The VS Contact Form plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 14.7. This makes it possible for unauthenticated attackers to bypass the Captcha Verification.

CVSS:
5.3
Affected:
up to 14.7
Fixed in:
14.8
Disclosed:
Mar 29, 2024

CVE-2024-30540 on NVD →

VS Contact Form <= 13.9 - Missing Authorization

medium

The VS Contact Form plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 13.9. Exact implications of this vulnerability are unknown.

CVSS:
5.3
Affected:
up to 13.9
Fixed in:
14.0
Disclosed:
Sep 5, 2023

CVE-2023-41862 on NVD →

VS Contact Form [very-simple-contact-form] < 11.6

unknown

[en] The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the page a likely target for spam bots.

Affected:
up to 11.6
Fixed in:
11.6
Disclosed:
Jun 20, 2022

CVE-2022-1801 on NVD →

VS Contact Form <= 11.5 - Reflected Cross-Site Scripting

medium

The VS Contact Form plugin for WordPress may be vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] parameter in versions up to, and including, 11.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...

CVSS:
6.1
Affected:
up to 11.5
Fixed in:
11.6
Disclosed:
May 25, 2022

VS Contact Form [very-simple-contact-form] < 11.6

unknown

The VS Contact Form plugin for WordPress may be vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] parameter in versions up to, and including, 11.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...

Affected:
up to 11.6
Fixed in:
11.6
Disclosed:
May 25, 2022

Very Simple Contact Form <= 11.5 - Captcha Bypass

high

The plugin Very Simple Contact Form in versions up to and including 11.4 uses a captcha that can be bypassed by bots. Version 11.5 removes the captcha code leaving the contact form vulnerable.

CVSS:
7.2
Affected:
up to 11.5
Fixed in:
11.6
Disclosed:
May 22, 2022

CVE-2022-1801 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database