plugin

Weforms Vulnerabilities

21 known security issues reported for the Weforms WordPress plugin. Most recent disclosed Mar 23, 2026.

3 high 8 medium

Running Weforms on your site? Check whether your installed version is affected.

Scan your site free

weForms – Easy Drag & Drop Contact Form Builder For WordPress <= 1.6.26 - Unauthenticated PHP Object Injection

high

The weForms – Easy Drag & Drop Contact Form Builder For WordPress plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.6.26 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the...

CVSS:
8.1
Affected:
up to 1.6.26
Fixed in:
1.6.27
Disclosed:
Mar 23, 2026

CVE-2026-32484 on NVD →

weForms - Authenticated (Subscriber+) Stored Cross-Site Scripting via Hidden Field Value via REST API vulnerability

medium

Authenticated (Subscriber+) Stored Cross-Site Scripting via Hidden Field Value via REST API vulnerability

CVSS:
6.5
Affected:
up to 1.6.27
Fixed in:
1.6.28
Disclosed:
Mar 11, 2026

weForms <= 1.6.27 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Hidden Field Value via REST API

medium

The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API entry submission endpoint in all versions up to, and including, 1.6.27. This is due to inconsistent input sanitization between the frontend AJAX handler and the REST API endpoint. When entries are submitted via the REST API (...

CVSS:
6.4
Affected:
up to 1.6.27
Fixed in:
1.6.28
Disclosed:
Mar 10, 2026

CVE-2026-2707 on NVD →

weForms &#8211; Easy Drag &amp; Drop Contact Form Builder For WordPress [weforms] <= 1.6.25 (unfixed)

unknown

[en] Missing Authorization vulnerability in BoldGrid weForms weforms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects weForms: from n/a through <= 1.6.25.

Affected:
up to 1.6.25
Fix:
No patched version reported
Disclosed:
Dec 30, 2025

CVE-2025-69028 on NVD →

weForms <= 1.6.25 - Missing Authorization

medium

The weForms – Easy Drag & Drop Contact Form Builder For WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.6.25. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.6.25
Fixed in:
1.6.26
Disclosed:
Dec 29, 2025

CVE-2025-69028 on NVD →

weForms &#8211; Easy Drag &amp; Drop Contact Form Builder For WordPress [weforms] < 1.6.24

unknown

<p>WordPress weForms Plugin <= 1.6.23 is vulnerable to Backdoor</p><p>Software: weForms</p><p>Link: https://wordpress.org/plugins/weforms/#developers</p><p>Affected Version <= 1.6.23</p>

Affected:
up to 1.6.24
Fixed in:
1.6.24
Disclosed:
Jul 3, 2024

Various Plugins <= Various Version - Use of Polyfill.io

medium

Multiple plugins for WordPress are vulnerable to malicious redirection in various versions. This is due to the use of Polyfill.io. Polyfill.io is a JavaScript library used to streamline delivery of content across older browsers and was taken over by malicious threat actors that used the service to redirect victims to m...

CVSS:
5.3
Affected:
up to 1.6.23
Fixed in:
1.6.24
Disclosed:
Jun 25, 2024

weForms &#8211; Easy Drag &amp; Drop Contact Form Builder For WordPress [weforms] < 1.6.24

unknown

Multiple plugins for WordPress are vulnerable to malicious redirection in various versions. This is due to the use of Polyfill.io. Polyfill.io is a JavaScript library used to streamline delivery of content across older browsers and was taken over by malicious threat actors that used the service to redirect victims to m...

Affected:
up to 1.6.24
Fixed in:
1.6.24
Disclosed:
Jun 25, 2024

weForms &#8211; Easy Drag &amp; Drop Contact Form Builder For WordPress [weforms] < 1.6.19

unknown

[en] Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.18.

Affected:
up to 1.6.19
Fixed in:
1.6.19
Disclosed:
Jun 12, 2024

CVE-2023-51524 on NVD →

weForms &#8211; Easy Drag &amp; Drop Contact Form Builder For WordPress [weforms] < 1.6.21

unknown

[en] Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.20.

Affected:
up to 1.6.21
Fixed in:
1.6.21
Disclosed:
Jun 9, 2024

CVE-2024-30512 on NVD →

weForms &#8211; Easy Drag &amp; Drop Contact Form Builder For WordPress [weforms] < 1.6.21

unknown

[en] Client-Side Enforcement of Server-Side Security vulnerability in weForms allows Removing Important Client Functionality.This issue affects weForms: from n/a through 1.6.20.

Affected:
up to 1.6.21
Fixed in:
1.6.21
Disclosed:
May 17, 2024

CVE-2024-32512 on NVD →

weForms <= 1.6.20 - Missing Authorization

medium

The weForms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the handle_frontend_submission() function in versions up to, and including, 1.6.20. This makes it possible for unauthenticated attackers to submit forms that are not open. CVE-2024-32512 is likely a duplicate of t...

CVSS:
5.3
Affected:
up to 1.6.20
Fixed in:
1.6.21
Disclosed:
Mar 28, 2024

CVE-2024-30512 on NVD →

weForms <= 1.6.21 - Unauthenticated Stored Cross-Site Scripting via Referer

high

The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versions up to, and including, 1.6.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will exe...

CVSS:
7.2
Affected:
up to 1.6.21
Fixed in:
1.6.22
Disclosed:
Mar 12, 2024

CVE-2024-0386 on NVD →

weForms &#8211; Easy Drag &amp; Drop Contact Form Builder For WordPress [weforms] < 1.6.22

unknown

[en] The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versions up to, and including, 1.6.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wil...

Affected:
up to 1.6.22
Fixed in:
1.6.22
Disclosed:
Mar 12, 2024

CVE-2024-0386 on NVD →

weForms &#8211; Easy Drag &amp; Drop Contact Form Builder For WordPress [weforms] < 1.6.18

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weForms weForms – Easy Drag & Drop Contact Form Builder For WordPress allows Stored XSS.This issue affects weForms – Easy Drag & Drop Contact Form Builder For WordPress: from n/a through 1.6.17.

Affected:
up to 1.6.18
Fixed in:
1.6.18
Disclosed:
Dec 29, 2023

CVE-2023-50896 on NVD →

weForms <= 1.6.18 - Missing Authorization via export_form_entries

medium

The weForms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'export_form_entries' function in versions up to, and including, 1.6.18. This makes it possible for authenticated attackers, with subscriber-level access and above, to export form entries.

CVSS:
6.5
Affected:
up to 1.6.18
Fixed in:
1.6.19
Disclosed:
Dec 27, 2023

CVE-2023-51524 on NVD →

weForms – Easy Drag & Drop Contact Form Builder For WordPress <= 1.6.17 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The weForms – Easy Drag & Drop Contact Form Builder For WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to 1.6.18 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrat...

CVSS:
4.4
Affected:
up to 1.6.17
Fixed in:
1.6.18
Disclosed:
Dec 26, 2023

CVE-2023-50896 on NVD →

weForms &#8211; Easy Drag &amp; Drop Contact Form Builder For WordPress [weforms] < 1.6.14

unknown

[en] The weForms WordPress plugin before 1.6.14 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 1.6.14
Fixed in:
1.6.14
Disclosed:
Aug 8, 2022

CVE-2022-2395 on NVD →

weForms <= 1.6.13 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via contact form settings in versions up to, and including, 1.6.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level permissions and above to inject arbitr...

CVSS:
5.5
Affected:
up to 1.6.13
Fixed in:
1.6.14
Disclosed:
Jul 12, 2022

CVE-2022-2395 on NVD →

weForms &#8211; Easy Drag &amp; Drop Contact Form Builder For WordPress [weforms] < 1.6.4

unknown

[en] WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.

Affected:
up to 1.6.4
Fixed in:
1.6.4
Disclosed:
Nov 4, 2020

CVE-2020-22276 on NVD →

WeForms <= 1.4.7 - CSV injection via form entry

high

WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.

CVSS:
8.6
Affected:
up to 1.4.7
Fixed in:
1.4.8
Disclosed:
Aug 13, 2020

CVE-2020-22276 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database