plugin

Wpgform Vulnerabilities

15 known security issues reported for the Wpgform WordPress plugin. Most recent disclosed Nov 28, 2022.

1 critical 2 high 2 medium

Running Wpgform on your site? Check whether your installed version is affected.

Scan your site free

Google Forms [wpgform] <= 0.95 (unfixed + closed)

unknown

[en] The Google Forms WordPress plugin through 0.95 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 0.95
Fix:
No patched version reported
Disclosed:
Nov 28, 2022

CVE-2022-3834 on NVD →

Google Forms <= 0.95 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Google Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 0.95 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbitrary web scripts in pages that will execut...

CVSS:
5.5
Affected:
up to 0.95
Fix:
No patched version reported
Disclosed:
Nov 3, 2022

CVE-2022-3834 on NVD →

Google Forms [wpgform] < 0.94 (closed)

unknown

[en] The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.

Affected:
up to 0.94
Fixed in:
0.94
Disclosed:
Aug 22, 2019

CVE-2018-20988 on NVD →

Google Forms <= 0.93 - Remote Code Execution

high

The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.

CVSS:
7.5
Affected:
up to 0.94
Fixed in:
0.94
Disclosed:
May 8, 2018

CVE-2018-20988 on NVD →

Google Forms [wpgform] < 0.92 (closed)

unknown

Unauthenticated Server-Side Request Forgery (SSRF) vulnerability found by Jouko Pynnönen in WordPress Google Forms plugin (versions <=0.91).

Affected:
up to 0.92
Fixed in:
0.92
Disclosed:
Jan 22, 2018

Google Forms < 0.92 - Unauthenticated Server Side Request Forgery

high

The Google Forms plugin for WordPress is vulnerable to Server Side Request Forgery in versions before 0.92. This allowed Unauthenticated attackers to proxy requests through the plugin to an attacker-controlled host, which could also lead to a reflected Cross-Site Scripting scenario.

CVSS:
7.2
Affected:
up to 0.92
Fixed in:
0.92
Disclosed:
Jan 20, 2018

Google Forms [wpgform] < 0.92 (closed)

unknown

The Google Forms plugin for WordPress is vulnerable to Server Side Request Forgery in versions before 0.92. This allowed Unauthenticated attackers to proxy requests through the plugin to an attacker-controlled host, which could also lead to a reflected Cross-Site Scripting scenario.

Affected:
up to 0.92
Fixed in:
0.92
Disclosed:
Jan 20, 2018

Google Forms <= 0.90 - Unauthenticated PHP Object injection

critical

The Google Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.90 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object. This vulnerability was confirmed to allow the unauthenticated attacker to remotely execute code.

CVSS:
9.8
Affected:
up to 0.91
Fixed in:
0.91
Disclosed:
Jan 7, 2017

Google Forms [wpgform] < 0.91 (closed)

unknown

The Google Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.90 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object. This vulnerability was confirmed to allow the unauthenticated attacker to remotely execute code.

Affected:
up to 0.91
Fixed in:
0.91
Disclosed:
Jan 7, 2017

Google Forms < 0.85 - Cross-Site Scripting

medium

The Google Forms plugin for WordPress is vulnerable to Cross-Site Scripting via the 'page' parameter in versions before 0.85 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 0.85
Fixed in:
0.85
Disclosed:
Jul 14, 2016

Google Forms [wpgform] < 0.85 (closed)

unknown

Because of this vulnerability, attackers can steal Administrators' session tokens or perform arbitrary actions on their behalf. Update the plugin.

Affected:
up to 0.85
Fixed in:
0.85
Disclosed:
Jul 14, 2016

Google Forms [wpgform] < 0.85 (closed)

unknown

The Google Forms plugin for WordPress is vulnerable to Cross-Site Scripting via the 'page' parameter in versions before 0.85 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 0.85
Fixed in:
0.85
Disclosed:
Jul 14, 2016

Google Forms [wpgform] < 0.92 (closed)

unknown

The Google Forms WordPress plugin was affected by an Unauthenticated Server-Side Request Forgery (SSRF) security vulnerability.

Affected:
up to 0.92
Fixed in:
0.92

Google Forms [wpgform] < 0.91 (closed)

unknown

The Google Forms WordPress plugin was affected by an Unauthenticated PHP Object Injection security vulnerability.

Affected:
up to 0.91
Fixed in:
0.91

Google Forms [wpgform] < 0.85 (closed)

unknown

The Google Forms WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 0.85
Fixed in:
0.85

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database