WPForms Pro <= 2.0.0.2 - Unauthenticated Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values
high
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all versions up to, and including, 2.0.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web sc...
- CVSS:
- 7.2
- Affected:
- up to 2.0.0.2
- Fixed in:
- 2.0.0.3
- Disclosed:
- Aug 20, 2026
CVE-2026-18409 on NVD →
WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Upload Init/Finalize Ordering
high
The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This is due to the file type validation occurring after chunk metadata and file contents have already been written to disk, and the assembled file not b...
- CVSS:
- 8.1
- Affected:
- up to 1.10.1.1
- Fixed in:
- 2.0.0
- Disclosed:
- Jul 24, 2026
CVE-2026-10818 on NVD →
WPForms Pro [wpforms] < 1.8.5.4
unknown
[en] The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including, 1.8.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...
- Affected:
- up to 1.8.5.4
- Fixed in:
- 1.8.5.4
- Disclosed:
- Jan 20, 2024
CVE-2023-7063 on NVD →
WPForms Pro 1.8.4 - 1.8.5.3 - Unauthenticated Stored Cross-Site Scripting via Form Submission
high
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions from 1.8.4 up to, and including, 1.8.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...
- CVSS:
- 7.2
- Affected:
- 1.8.4 – 1.8.5.3
- Fixed in:
- 1.8.5.4
- Disclosed:
- Jan 19, 2024
CVE-2023-7063 on NVD →
WPForms Pro [wpforms] < 1.8.1.3
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 versions.
- Affected:
- up to 1.8.1.3
- Fixed in:
- 1.8.1.3
- Disclosed:
- Jun 22, 2023
CVE-2023-30500 on NVD →
Contact Form by WPForms (Free and Premium) <= 1.8.1.2 - Reflected Cross-Site Scripting
medium
The Contact Form by WPForms (Free and Premium) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.8.1.2 due to insufficient input sanitization and output escaping on debug data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- up to 1.8.1.2
- Fixed in:
- 1.8.1.3
- Disclosed:
- Jun 20, 2023
CVE-2023-30500 on NVD →
WPForms Pro [wpforms] < 1.7.7
unknown
[en] The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Nov 14, 2022
CVE-2022-3574 on NVD →
WPForms Pro <= 1.7.6 - CSV Injection
high
The WPForms Pro plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.7.6. This allows attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
- CVSS:
- 7.2
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.7
- Disclosed:
- Oct 19, 2022
CVE-2022-3574 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database