plugin

Wp Forms Connector Vulnerabilities

2 known security issues reported for the Wp Forms Connector WordPress plugin. Most recent disclosed Jun 23, 2026.

2 high

Running Wp Forms Connector on your site? Check whether your installed version is affected.

Scan your site free

WP Forms Connector <= 1.8 - Missing Authorization to Unauthenticated Information Exposure via 'user/list' REST Endpoint

high

The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/list/<id> (callback userDetail()) with permission_callback set to '__return_true', and the function's home-grown authentication only verifies that t...

CVSS:
7.5
Affected:
up to 1.8
Fix:
No patched version reported
Disclosed:
Jun 23, 2026

CVE-2026-9178 on NVD →

WP Forms Connector <= 1.8 - Unauthenticated SQL Injection via 'order' Parameter

high

The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and including 1.8. This is due to insufficient escaping on the user-supplied 'order' parameter (read directly from $_GET['order'] into $shorting) and the l...

CVSS:
7.5
Affected:
up to 1.8
Fix:
No patched version reported
Disclosed:
Jun 23, 2026

CVE-2026-9179 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database