Google Forms [wpgform] <= 0.95 (unfixed + closed)
unknown
[en] The Google Forms WordPress plugin through 0.95 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 0.95
- Fix:
- No patched version reported
- Disclosed:
- Nov 28, 2022
CVE-2022-3834 on NVD →
Google Forms <= 0.95 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Google Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in versions up to, and including, 0.95 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbitrary web scripts in pages that will execut...
- CVSS:
- 5.5
- Affected:
- up to 0.95
- Fix:
- No patched version reported
- Disclosed:
- Nov 3, 2022
CVE-2022-3834 on NVD →
Google Forms [wpgform] < 0.94 (closed)
unknown
[en] The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.
- Affected:
- up to 0.94
- Fixed in:
- 0.94
- Disclosed:
- Aug 22, 2019
CVE-2018-20988 on NVD →
Google Forms <= 0.93 - Remote Code Execution
high
The wpgform plugin before 0.94 for WordPress has eval injection in the CAPTCHA calculation.
- CVSS:
- 7.5
- Affected:
- up to 0.94
- Fixed in:
- 0.94
- Disclosed:
- May 8, 2018
CVE-2018-20988 on NVD →
Google Forms [wpgform] < 0.92 (closed)
unknown
Unauthenticated Server-Side Request Forgery (SSRF) vulnerability found by Jouko Pynnönen in WordPress Google Forms plugin (versions <=0.91).
- Affected:
- up to 0.92
- Fixed in:
- 0.92
- Disclosed:
- Jan 22, 2018
Google Forms < 0.92 - Unauthenticated Server Side Request Forgery
high
The Google Forms plugin for WordPress is vulnerable to Server Side Request Forgery in versions before 0.92. This allowed Unauthenticated attackers to proxy requests through the plugin to an attacker-controlled host, which could also lead to a reflected Cross-Site Scripting scenario.
- CVSS:
- 7.2
- Affected:
- up to 0.92
- Fixed in:
- 0.92
- Disclosed:
- Jan 20, 2018
Google Forms [wpgform] < 0.92 (closed)
unknown
The Google Forms plugin for WordPress is vulnerable to Server Side Request Forgery in versions before 0.92. This allowed Unauthenticated attackers to proxy requests through the plugin to an attacker-controlled host, which could also lead to a reflected Cross-Site Scripting scenario.
- Affected:
- up to 0.92
- Fixed in:
- 0.92
- Disclosed:
- Jan 20, 2018
Google Forms <= 0.90 - Unauthenticated PHP Object injection
critical
The Google Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.90 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object. This vulnerability was confirmed to allow the unauthenticated attacker to remotely execute code.
- CVSS:
- 9.8
- Affected:
- up to 0.91
- Fixed in:
- 0.91
- Disclosed:
- Jan 7, 2017
Google Forms [wpgform] < 0.91 (closed)
unknown
The Google Forms plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 0.90 via deserialization of untrusted input. This allows unauthenticated attackers to inject a PHP Object. This vulnerability was confirmed to allow the unauthenticated attacker to remotely execute code.
- Affected:
- up to 0.91
- Fixed in:
- 0.91
- Disclosed:
- Jan 7, 2017
Google Forms < 0.85 - Cross-Site Scripting
medium
The Google Forms plugin for WordPress is vulnerable to Cross-Site Scripting via the 'page' parameter in versions before 0.85 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 0.85
- Fixed in:
- 0.85
- Disclosed:
- Jul 14, 2016
Google Forms [wpgform] < 0.85 (closed)
unknown
Because of this vulnerability, attackers can steal Administrators' session tokens or perform arbitrary actions on their behalf.
Update the plugin.
- Affected:
- up to 0.85
- Fixed in:
- 0.85
- Disclosed:
- Jul 14, 2016
Google Forms [wpgform] < 0.85 (closed)
unknown
The Google Forms plugin for WordPress is vulnerable to Cross-Site Scripting via the 'page' parameter in versions before 0.85 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 0.85
- Fixed in:
- 0.85
- Disclosed:
- Jul 14, 2016
Google Forms [wpgform] < 0.92 (closed)
unknown
The Google Forms WordPress plugin was affected by an Unauthenticated Server-Side Request Forgery (SSRF) security vulnerability.
- Affected:
- up to 0.92
- Fixed in:
- 0.92
Google Forms [wpgform] < 0.91 (closed)
unknown
The Google Forms WordPress plugin was affected by an Unauthenticated PHP Object Injection security vulnerability.
- Affected:
- up to 0.91
- Fixed in:
- 0.91
Google Forms [wpgform] < 0.85 (closed)
unknown
The Google Forms WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 0.85
- Fixed in:
- 0.85
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database