WPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content
medium
The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization...
- CVSS:
- 4.9
- Affected:
- up to 2.0.0.1
- Fixed in:
- 2.0.0.2
- Disclosed:
- Jul 20, 2026
CVE-2026-15782 on NVD →
WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name
medium
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 1.10.2 This is due to `get_reply_to_address()` processing the Reply-To display name throu...
- CVSS:
- 5.3
- Affected:
- up to 1.10.2
- Fixed in:
- 1.10.2.1
- Disclosed:
- Jun 30, 2026
CVE-2026-12127 on NVD →
WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint
medium
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to and including 1.10.0.1. This is due to the PayPal Commerce webhook endpoint processing unauthenticated JSON webhook payload...
- CVSS:
- 5.3
- Affected:
- up to 1.10.0.4
- Fixed in:
- 1.10.0.5
- Disclosed:
- Jun 5, 2026
CVE-2026-7792 on NVD →
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More <= 1.10.0.4 - Missing Authorization
medium
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.10.0.4. This makes it possible for unauthenticated attackers to perform an unauthori...
- CVSS:
- 5.3
- Affected:
- up to 1.10.0.4
- Fixed in:
- 1.10.0.5
- Disclosed:
- May 28, 2026
CVE-2026-48835 on NVD →
Contact Form by WPForms <= 1.10.0.2 - Cross-Site Request Forgery
medium
The Contact Form by WPForms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.0.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted...
- CVSS:
- 4.3
- Affected:
- up to 1.10.0.2
- Fixed in:
- 1.10.0.3
- Disclosed:
- Mar 31, 2026
CVE-2026-40764 on NVD →
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More <= 1.9.8.7 - Unauthenticated Sensitive Information Exposure
medium
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.8.7. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.
- CVSS:
- 5.3
- Affected:
- up to 1.9.8.7
- Fixed in:
- 1.9.9.2
- Disclosed:
- Mar 23, 2026
CVE-2026-25339 on NVD →
Contact Form by WPForms <= 1.9.9.3 - Missing Authorization
medium
The Contact Form by WPForms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.9.9.3. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.9.9.3
- Fixed in:
- 1.9.9.4
- Disclosed:
- Mar 7, 2026
CVE-2026-32446 on NVD →
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] <= 1.7.8 (unfixed)
unknown
[en] WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attackers can inject malicious scripts through the ListTable.php endpoint to execute arbitrary JavaScript in victim's browser.
- Affected:
- up to 1.7.8
- Fix:
- No patched version reported
- Disclosed:
- Jan 13, 2026
CVE-2020-36919 on NVD →
WPForms Lite <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'start_timestamp' Parameter
medium
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the start_timestamp parameter in all versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible...
- CVSS:
- 5.4
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.5.1
- Disclosed:
- May 9, 2025
CVE-2025-3794 on NVD →
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.9.3.2
unknown
[en] The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fieldHTML’ parameter in all versions up to, and including, 1.9.3.1 due to insufficient input sanitization and output escaping. This makes it possi...
- Affected:
- up to 1.9.3.2
- Fixed in:
- 1.9.3.2
- Disclosed:
- Feb 4, 2025
CVE-2024-13403 on NVD →
WPForms Lite <= 1.9.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameter
medium
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fieldHTML’ parameter in all versions up to, and including, 1.9.3.1 due to insufficient input sanitization and output escaping. This makes it possible f...
- CVSS:
- 6.4
- Affected:
- up to 1.9.3.1
- Fixed in:
- 1.9.3.2
- Disclosed:
- Feb 3, 2025
CVE-2024-13403 on NVD →
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.9.2.3
unknown
[en] Missing Authorization vulnerability in WPForms Contact Form by WPForms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through 1.9.2.2.
- Affected:
- up to 1.9.2.3
- Fixed in:
- 1.9.2.3
- Disclosed:
- Jan 7, 2025
CVE-2024-56276 on NVD →
Contact Form by WPForms <= 1.9.2.2 - Missing Authorization
medium
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.9.2.2. This makes it possible for authenticated attackers, with Contributor-leve...
- CVSS:
- 4.3
- Affected:
- up to 1.9.2.2
- Fixed in:
- 1.9.2.3
- Disclosed:
- Jan 3, 2025
CVE-2024-56276 on NVD →
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.9.2.3
unknown
[en] The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 1.9.2.3
- Fixed in:
- 1.9.2.3
- Disclosed:
- Dec 26, 2024
CVE-2024-11223 on NVD →
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] >= 1.8.4 - <= 1.9.2.1
unknown
[en] The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...
- Affected:
- 1.8.4 – 1.9.2.1
- Fixed in:
- 1.9.2.1
- Disclosed:
- Dec 10, 2024
CVE-2024-11205 on NVD →
WPForms 1.8.4 - 1.9.2.1 - Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation
high
The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to refu...
- CVSS:
- 8.5
- Affected:
- 1.8.4 – 1.9.2.1
- Fixed in:
- 1.9.2.2
- Disclosed:
- Dec 9, 2024
CVE-2024-11205 on NVD →
WPForms <= 1.9.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenti...
- CVSS:
- 4.4
- Affected:
- up to 1.9.2.2
- Fixed in:
- 1.9.2.3
- Disclosed:
- Dec 5, 2024
CVE-2024-11223 on NVD →
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.9.1.6
unknown
[en] The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 1.9.1.6
- Fixed in:
- 1.9.1.6
- Disclosed:
- Nov 25, 2024
CVE-2024-7056 on NVD →
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.9.2.1
unknown
[en] The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.1.6. This is due to missing or incorrect nonce validation on the process_admin_ui function. This makes it possible...
- Affected:
- up to 1.9.2.1
- Fixed in:
- 1.9.2.1
- Disclosed:
- Nov 13, 2024
CVE-2024-10593 on NVD →
WPForms – Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion
medium
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.1.6. This is due to missing or incorrect nonce validation on the process_admin_ui function. This makes it possible for...
- CVSS:
- 4.3
- Affected:
- up to 1.9.1.6
- Fixed in:
- 1.9.2.1
- Disclosed:
- Nov 12, 2024
CVE-2024-10593 on NVD →
WPForms <= 1.9.1.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenti...
- CVSS:
- 4.4
- Affected:
- up to 1.9.1.5
- Fixed in:
- 1.9.1.6
- Disclosed:
- Nov 4, 2024
CVE-2024-7056 on NVD →
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.8.8.2
unknown
[en] The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to price manipulation in versions up to, and including, 1.8.7.2. This is due to a lack of controls on several product parameters. This makes it possible for unauthenticated attackers to manipulate prices, produc...
- Affected:
- up to 1.8.8.2
- Fixed in:
- 1.8.8.2
- Disclosed:
- May 2, 2024
CVE-2024-3649 on NVD →
Contact Form by WPForms – Drag & Drop Form Builder for WordPress <= 1.8.7.2 - Unauthenticated Price Manipulation
medium
The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to price manipulation in versions up to, and including, 1.8.7.2. This is due to a lack of controls on several product parameters. This makes it possible for unauthenticated attackers to manipulate prices, product inf...
- CVSS:
- 5.3
- Affected:
- up to 1.8.7.2
- Fixed in:
- 1.8.8.2
- Disclosed:
- May 1, 2024
CVE-2024-3649 on NVD →
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.8.1.3
unknown
[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 versions.
- Affected:
- up to 1.8.1.3
- Fixed in:
- 1.8.1.3
- Disclosed:
- Jun 22, 2023
CVE-2023-30500 on NVD →
Contact Form by WPForms (Free and Premium) <= 1.8.1.2 - Reflected Cross-Site Scripting
medium
The Contact Form by WPForms (Free and Premium) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.8.1.2 due to insufficient input sanitization and output escaping on debug data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- up to 1.8.1.2
- Fixed in:
- 1.8.1.3
- Disclosed:
- Jun 20, 2023
CVE-2023-30500 on NVD →
Contact Form by WPForms <= 1.7.5.3 - Authenticated (Administrator+) Arbitrary File Access via Path Traversal
medium
The Contact Form by WPForms plugin for WordPress is vulnerable to Directory Traversal via email template paths in versions up to, and including, 1.7.5.3. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 6.8
- Affected:
- up to 1.7.5.3
- Fixed in:
- 1.7.5.5
- Disclosed:
- Sep 19, 2022
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.7.5.5
unknown
The Contact Form by WPForms plugin for WordPress is vulnerable to Directory Traversal via email template paths in versions up to, and including, 1.7.5.3. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- Affected:
- up to 1.7.5.5
- Fixed in:
- 1.7.5.5
- Disclosed:
- Sep 19, 2022
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.7.5.5
unknown
Authenticated Arbitrary File Access vulnerability discovered by Sybre Waaijer in WordPress Contact Form by WPForms plugin (versions <= 1.7.5.3).
Update the WordPress Contact Form by WPForms plugin to the latest available version (at least 1.7.5.5).
- Affected:
- up to 1.7.5.5
- Fixed in:
- 1.7.5.5
- Disclosed:
- Sep 19, 2022
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.6.0.2
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Fortinet in WordPress Contact Form by WPForms plugin (versions <= 1.6.0.1).
- Affected:
- up to 1.6.0.2
- Fixed in:
- 1.6.0.2
- Disclosed:
- Jul 1, 2020
Contact Form by WPForms <= 1.6.0.1 - Cross-Site Scripting
high
The Contact Form by WPForms plugin for WordPress has a Cross-Site Scripting vulnerability, which is caused by improper input sanitization of user input via the choice label parameter in versions up to, and including, 1.6.0.1.
- CVSS:
- 7.2
- Affected:
- up to 1.6.0.2
- Fixed in:
- 1.6.0.2
- Disclosed:
- May 21, 2020
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.6.0.2
unknown
The Contact Form by WPForms plugin for WordPress has a Cross-Site Scripting vulnerability, which is caused by improper input sanitization of user input via the choice label parameter in versions up to, and including, 1.6.0.1.
- Affected:
- up to 1.6.0.2
- Fixed in:
- 1.6.0.2
- Disclosed:
- May 21, 2020
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.5.9
unknown
[en] A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.
- Affected:
- up to 1.5.9
- Fixed in:
- 1.5.9
- Disclosed:
- Mar 11, 2020
CVE-2020-10385 on NVD →
Contact Form by WPForms <= 1.5.8.2 - Stored Cross-Site Scripting
medium
A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.
- CVSS:
- 6.4
- Affected:
- up to 1.5.9
- Fixed in:
- 1.5.9
- Disclosed:
- Feb 18, 2020
CVE-2020-10385 on NVD →
Contact Form by WPForms <= 1.4.8 - Reflected Cross-Site Scripting
high
The Contact Form by WPForms for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...
- CVSS:
- 7.1
- Affected:
- up to 1.4.8.1
- Fixed in:
- 1.4.8.1
- Disclosed:
- Dec 10, 2018
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.4.8.1
unknown
The Contact Form by WPForms for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...
- Affected:
- up to 1.4.8.1
- Fixed in:
- 1.4.8.1
- Disclosed:
- Dec 10, 2018
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.4.8.1
unknown
Unauthenticated Cross-Site Scripting (XSS) vulnerability found by RIPS Technologies in WordPress Contact Form by WPForms plugin (versions <= 1.4.8).
- Affected:
- up to 1.4.8.1
- Fixed in:
- 1.4.8.1
- Disclosed:
- Dec 10, 2018
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.4.8
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by RIPS Technologies in WordPress Contact Form by WPForms plugin (versions <= 1.4.7).
- Affected:
- up to 1.4.8
- Fixed in:
- 1.4.8
- Disclosed:
- Dec 7, 2018
Contact Form by WPForms – Drag & Drop Form Builder for WordPress <= 1.4.7.2 - Stored Cross-Site Scripting
medium
The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tab parameter in versions up to, and including 1.4.7. This makes it possible for lower-privileged attackers to inject arbitrary web scripts in administrative pages that execute...
- CVSS:
- 6.4
- Affected:
- up to 1.4.8
- Fixed in:
- 1.4.8
- Disclosed:
- Sep 18, 2018
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.4.8
unknown
The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tab parameter in versions up to, and including 1.4.7. This makes it possible for lower-privileged attackers to inject arbitrary web scripts in administrative pages that execute...
- Affected:
- up to 1.4.8
- Fixed in:
- 1.4.8
- Disclosed:
- Sep 18, 2018
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.4.8
unknown
The Contact Form by WPForms – Drag & Drop Form Builder for WordPress WordPress plugin was affected by an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.4.8
- Fixed in:
- 1.4.8
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.4.8.1
unknown
RIPS Technologies identified an Unauthenticated Cross-Site Scripting (XSS) vulnerability within the WPForms WordPress plugin during their WordPress Security Calendar 2018 research. The date parameter was embedded within JavaScript code without any validation or encoding.
- Affected:
- up to 1.4.8.1
- Fixed in:
- 1.4.8.1
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.6.0.2
unknown
Vishnupriya Ilango from Fortinet's FortiGuard Labs discovered an authenticated stored Cross-Site Scripting issue via the choice label parameter inside the form builder that interacts with live preview.
- Affected:
- up to 1.6.0.2
- Fixed in:
- 1.6.0.2
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.7.5.5
unknown
The plugin does not validate email template paths, which could allow high privilege users such as admin (for example in multisite) to access arbitrary files on the web server via a path traversal attack
- Affected:
- up to 1.7.5.5
- Fixed in:
- 1.7.5.5
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.9.5.1
unknown
- Affected:
- up to 1.9.5.1
- Fixed in:
- 1.9.5.1
CVE-2025-3794 on NVD →