weForms – Easy Drag & Drop Contact Form Builder For WordPress <= 1.6.26 - Unauthenticated PHP Object Injection
high
The weForms – Easy Drag & Drop Contact Form Builder For WordPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.26 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the...
- CVSS:
- 8.1
- Affected:
- up to 1.6.26
- Fixed in:
- 1.6.27
- Disclosed:
- Mar 23, 2026
CVE-2026-32484 on NVD →
weForms - Authenticated (Subscriber+) Stored Cross-Site Scripting via Hidden Field Value via REST API vulnerability
medium
Authenticated (Subscriber+) Stored Cross-Site Scripting via Hidden Field Value via REST API vulnerability
- CVSS:
- 6.5
- Affected:
- up to 1.6.27
- Fixed in:
- 1.6.28
- Disclosed:
- Mar 11, 2026
weForms <= 1.6.27 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Hidden Field Value via REST API
medium
The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API entry submission endpoint in all versions up to, and including, 1.6.27. This is due to inconsistent input sanitization between the frontend AJAX handler and the REST API endpoint. When entries are submitted via the REST API (...
- CVSS:
- 6.4
- Affected:
- up to 1.6.27
- Fixed in:
- 1.6.28
- Disclosed:
- Mar 10, 2026
CVE-2026-2707 on NVD →
weForms – Easy Drag & Drop Contact Form Builder For WordPress [weforms] <= 1.6.25 (unfixed)
unknown
[en] Missing Authorization vulnerability in BoldGrid weForms weforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects weForms: from n/a through <= 1.6.25.
- Affected:
- up to 1.6.25
- Fix:
- No patched version reported
- Disclosed:
- Dec 30, 2025
CVE-2025-69028 on NVD →
weForms <= 1.6.25 - Missing Authorization
medium
The weForms – Easy Drag & Drop Contact Form Builder For WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.6.25. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.6.25
- Fixed in:
- 1.6.26
- Disclosed:
- Dec 29, 2025
CVE-2025-69028 on NVD →
weForms – Easy Drag & Drop Contact Form Builder For WordPress [weforms] < 1.6.24
unknown
<p>WordPress weForms Plugin <= 1.6.23 is vulnerable to Backdoor</p><p>Software: weForms</p><p>Link: https://wordpress.org/plugins/weforms/#developers</p><p>Affected Version <= 1.6.23</p>
- Affected:
- up to 1.6.24
- Fixed in:
- 1.6.24
- Disclosed:
- Jul 3, 2024
Various Plugins <= Various Version - Use of Polyfill.io
medium
Multiple plugins for WordPress are vulnerable to malicious redirection in various versions. This is due to the use of Polyfill.io. Polyfill.io is a JavaScript library used to streamline delivery of content across older browsers and was taken over by malicious threat actors that used the service to redirect victims to m...
- CVSS:
- 5.3
- Affected:
- up to 1.6.23
- Fixed in:
- 1.6.24
- Disclosed:
- Jun 25, 2024
weForms – Easy Drag & Drop Contact Form Builder For WordPress [weforms] < 1.6.24
unknown
Multiple plugins for WordPress are vulnerable to malicious redirection in various versions. This is due to the use of Polyfill.io. Polyfill.io is a JavaScript library used to streamline delivery of content across older browsers and was taken over by malicious threat actors that used the service to redirect victims to m...
- Affected:
- up to 1.6.24
- Fixed in:
- 1.6.24
- Disclosed:
- Jun 25, 2024
weForms – Easy Drag & Drop Contact Form Builder For WordPress [weforms] < 1.6.19
unknown
[en] Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.18.
- Affected:
- up to 1.6.19
- Fixed in:
- 1.6.19
- Disclosed:
- Jun 12, 2024
CVE-2023-51524 on NVD →
weForms – Easy Drag & Drop Contact Form Builder For WordPress [weforms] < 1.6.21
unknown
[en] Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.20.
- Affected:
- up to 1.6.21
- Fixed in:
- 1.6.21
- Disclosed:
- Jun 9, 2024
CVE-2024-30512 on NVD →
weForms – Easy Drag & Drop Contact Form Builder For WordPress [weforms] < 1.6.21
unknown
[en] Client-Side Enforcement of Server-Side Security vulnerability in weForms allows Removing Important Client Functionality.This issue affects weForms: from n/a through 1.6.20.
- Affected:
- up to 1.6.21
- Fixed in:
- 1.6.21
- Disclosed:
- May 17, 2024
CVE-2024-32512 on NVD →
weForms <= 1.6.20 - Missing Authorization
medium
The weForms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the handle_frontend_submission() function in versions up to, and including, 1.6.20. This makes it possible for unauthenticated attackers to submit forms that are not open. CVE-2024-32512 is likely a duplicate of t...
- CVSS:
- 5.3
- Affected:
- up to 1.6.20
- Fixed in:
- 1.6.21
- Disclosed:
- Mar 28, 2024
CVE-2024-30512 on NVD →
weForms <= 1.6.21 - Unauthenticated Stored Cross-Site Scripting via Referer
high
The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versions up to, and including, 1.6.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will exe...
- CVSS:
- 7.2
- Affected:
- up to 1.6.21
- Fixed in:
- 1.6.22
- Disclosed:
- Mar 12, 2024
CVE-2024-0386 on NVD →
weForms – Easy Drag & Drop Contact Form Builder For WordPress [weforms] < 1.6.22
unknown
[en] The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versions up to, and including, 1.6.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wil...
- Affected:
- up to 1.6.22
- Fixed in:
- 1.6.22
- Disclosed:
- Mar 12, 2024
CVE-2024-0386 on NVD →
weForms – Easy Drag & Drop Contact Form Builder For WordPress [weforms] < 1.6.18
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weForms weForms – Easy Drag & Drop Contact Form Builder For WordPress allows Stored XSS.This issue affects weForms – Easy Drag & Drop Contact Form Builder For WordPress: from n/a through 1.6.17.
- Affected:
- up to 1.6.18
- Fixed in:
- 1.6.18
- Disclosed:
- Dec 29, 2023
CVE-2023-50896 on NVD →
weForms <= 1.6.18 - Missing Authorization via export_form_entries
medium
The weForms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'export_form_entries' function in versions up to, and including, 1.6.18. This makes it possible for authenticated attackers, with subscriber-level access and above, to export form entries.
- CVSS:
- 6.5
- Affected:
- up to 1.6.18
- Fixed in:
- 1.6.19
- Disclosed:
- Dec 27, 2023
CVE-2023-51524 on NVD →
weForms – Easy Drag & Drop Contact Form Builder For WordPress <= 1.6.17 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The weForms – Easy Drag & Drop Contact Form Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to 1.6.18 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrat...
- CVSS:
- 4.4
- Affected:
- up to 1.6.17
- Fixed in:
- 1.6.18
- Disclosed:
- Dec 26, 2023
CVE-2023-50896 on NVD →
weForms – Easy Drag & Drop Contact Form Builder For WordPress [weforms] < 1.6.14
unknown
[en] The weForms WordPress plugin before 1.6.14 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 1.6.14
- Fixed in:
- 1.6.14
- Disclosed:
- Aug 8, 2022
CVE-2022-2395 on NVD →
weForms <= 1.6.13 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via contact form settings in versions up to, and including, 1.6.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject arbitr...
- CVSS:
- 5.5
- Affected:
- up to 1.6.13
- Fixed in:
- 1.6.14
- Disclosed:
- Jul 12, 2022
CVE-2022-2395 on NVD →
weForms – Easy Drag & Drop Contact Form Builder For WordPress [weforms] < 1.6.4
unknown
[en] WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.4
- Disclosed:
- Nov 4, 2020
CVE-2020-22276 on NVD →
WeForms <= 1.4.7 - CSV injection via form entry
high
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
- CVSS:
- 8.6
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.8
- Disclosed:
- Aug 13, 2020
CVE-2020-22276 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database