VS Contact Form [very-simple-contact-form] < 14.0
unknown
[en] Weak Authentication vulnerability in Guido VS Contact Form allows Authentication Abuse.This issue affects VS Contact Form: from n/a through 14.0.
- Affected:
- up to 14.0
- Fixed in:
- 14.0
- Disclosed:
- Dec 13, 2024
CVE-2023-41862 on NVD →
VS Contact Form [very-simple-contact-form] < 14.8
unknown
[en] Guessable CAPTCHA vulnerability in Guido VS Contact Form allows Functionality Bypass.This issue affects VS Contact Form: from n/a through 14.7.
- Affected:
- up to 14.8
- Fixed in:
- 14.8
- Disclosed:
- May 17, 2024
CVE-2024-30540 on NVD →
VS Contact Form <= 14.7 - CAPTCHA Bypass
medium
The VS Contact Form plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 14.7. This makes it possible for unauthenticated attackers to bypass the Captcha Verification.
- CVSS:
- 5.3
- Affected:
- up to 14.7
- Fixed in:
- 14.8
- Disclosed:
- Mar 29, 2024
CVE-2024-30540 on NVD →
VS Contact Form <= 13.9 - Missing Authorization
medium
The VS Contact Form plugin for WordPress is vulnerable to missing authorization in versions up to, and including, 13.9. Exact implications of this vulnerability are unknown.
- CVSS:
- 5.3
- Affected:
- up to 13.9
- Fixed in:
- 14.0
- Disclosed:
- Sep 5, 2023
CVE-2023-41862 on NVD →
VS Contact Form [very-simple-contact-form] < 11.6
unknown
[en] The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check, rendering the page a likely target for spam bots.
- Affected:
- up to 11.6
- Fixed in:
- 11.6
- Disclosed:
- Jun 20, 2022
CVE-2022-1801 on NVD →
VS Contact Form <= 11.5 - Reflected Cross-Site Scripting
medium
The VS Contact Form plugin for WordPress may be vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] parameter in versions up to, and including, 11.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...
- CVSS:
- 6.1
- Affected:
- up to 11.5
- Fixed in:
- 11.6
- Disclosed:
- May 25, 2022
VS Contact Form [very-simple-contact-form] < 11.6
unknown
The VS Contact Form plugin for WordPress may be vulnerable to Reflected Cross-Site Scripting via the $_SERVER['REQUEST_URI'] parameter in versions up to, and including, 11.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i...
- Affected:
- up to 11.6
- Fixed in:
- 11.6
- Disclosed:
- May 25, 2022
Very Simple Contact Form <= 11.5 - Captcha Bypass
high
The plugin Very Simple Contact Form in versions up to and including 11.4 uses a captcha that can be bypassed by bots. Version 11.5 removes the captcha code leaving the contact form vulnerable.
- CVSS:
- 7.2
- Affected:
- up to 11.5
- Fixed in:
- 11.6
- Disclosed:
- May 22, 2022
CVE-2022-1801 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database