plugin

Wpforms Vulnerabilities

8 known security issues reported for the Wpforms WordPress plugin. Most recent disclosed Aug 20, 2026.

4 high 1 medium

Running Wpforms on your site? Check whether your installed version is affected.

Scan your site free

WPForms Pro <= 2.0.0.2 - Unauthenticated Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values

high

The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all versions up to, and including, 2.0.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...

CVSS:
7.2
Affected:
up to 2.0.0.2
Fixed in:
2.0.0.3
Disclosed:
Aug 20, 2026

CVE-2026-18409 on NVD →

WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering

high

The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not b...

CVSS:
8.1
Affected:
up to 1.10.1.1
Fixed in:
2.0.0
Disclosed:
Jul 24, 2026

CVE-2026-10818 on NVD →

WPForms Pro [wpforms] < 1.8.5.4

unknown

[en] The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including, 1.8.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

Affected:
up to 1.8.5.4
Fixed in:
1.8.5.4
Disclosed:
Jan 20, 2024

CVE-2023-7063 on NVD →

WPForms Pro 1.8.4 - 1.8.5.3 - Unauthenticated Stored Cross-Site Scripting via Form Submission

high

The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions from 1.8.4 up to, and including, 1.8.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

CVSS:
7.2
Affected:
1.8.4 – 1.8.5.3
Fixed in:
1.8.5.4
Disclosed:
Jan 19, 2024

CVE-2023-7063 on NVD →

WPForms Pro [wpforms] < 1.8.1.3

unknown

[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 versions.

Affected:
up to 1.8.1.3
Fixed in:
1.8.1.3
Disclosed:
Jun 22, 2023

CVE-2023-30500 on NVD →

Contact Form by WPForms (Free and Premium) <= 1.8.1.2 - Reflected Cross-Site Scripting

medium

The Contact Form by WPForms (Free and Premium) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.8.1.2 due to insufficient input sanitization and output escaping on debug data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
6.1
Affected:
up to 1.8.1.2
Fixed in:
1.8.1.3
Disclosed:
Jun 20, 2023

CVE-2023-30500 on NVD →

WPForms Pro [wpforms] < 1.7.7

unknown

[en] The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.

Affected:
up to 1.7.7
Fixed in:
1.7.7
Disclosed:
Nov 14, 2022

CVE-2022-3574 on NVD →

WPForms Pro <= 1.7.6 - CSV Injection

high

The WPForms Pro plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.7.6. This allows attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

CVSS:
7.2
Affected:
up to 1.7.6
Fixed in:
1.7.7
Disclosed:
Oct 19, 2022

CVE-2022-3574 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database