Vulnerabilities and security researches forwpforms-lite wpforms-lite
Direction: ascendingJun 07, 2024
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2020-10385
- CVE, Research URL
- Date
- Mar 24, 2020
- Research Description
- A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.
- Affected versions
-
max 1.5.9.
- Status
-
vulnerable
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2023-30500
- CVE, Research URL
- Date
- Jun 22, 2023
- Research Description
- Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 versions.
- Affected versions
-
max 1.8.1.3.
- Status
-
vulnerable
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2024-3649
- CVE, Research URL
- Date
- May 02, 2024
- Research Description
- The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to price manipulation in versions up to, and including, 1.8.7.2. This is due to a lack of controls on several product parameters. This makes it possible for unauthenticated attackers to manipulate prices, product information, and quantities for purchases made via the Stripe payment integration.
- Affected versions
-
max 1.8.8.2.
- Status
-
vulnerable
Nov 13, 2024
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2024-10593
- CVE, Research URL
- Date
- Nov 13, 2024
- Research Description
- The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.1.6. This is due to missing or incorrect nonce validation on the process_admin_ui function. This makes it possible for unauthenticated attackers to delete WPForm logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
- Affected versions
-
max 1.9.2.1.
- Status
-
vulnerable
Nov 20, 2024
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2024-7056
- CVE, Research URL
- Date
- Nov 25, 2024
- Research Description
- The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected versions
-
max 1.9.1.6.
- Status
-
vulnerable
Dec 11, 2024
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2024-11205
- CVE, Research URL
- Date
- Dec 10, 2024
- Research Description
- The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to refund payments and cancel subscriptions.
- Affected versions
-
Min 1.8.4, max 1.9.2.1.
- Status
-
vulnerable
Dec 25, 2024
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2024-11223
- CVE, Research URL
- Date
- Dec 26, 2024
- Research Description
- The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected versions
-
max 1.9.2.3.
- Status
-
vulnerable
Jan 09, 2025
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2024-56276
- CVE, Research URL
- Date
- Jan 07, 2025
- Research Description
- Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through <= 1.9.2.2.
- Affected versions
-
max 1.9.2.3.
- Status
-
vulnerable
Feb 05, 2025
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2024-13403
- CVE, Research URL
- Date
- Feb 04, 2025
- Research Description
- The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fieldHTML’ parameter in all versions up to, and including, 1.9.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.9.3.2.
- Status
-
vulnerable
May 10, 2025
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2025-3794
- CVE, Research URL
- Date
- May 10, 2025
- Research Description
- The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the start_timestamp parameter in all versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 1.9.5.1.
- Status
-
vulnerable
Jan 27, 2026
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2020-36919
- CVE, Research URL
- Date
- Jan 14, 2026
- Research Description
- WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attackers can inject malicious scripts through the ListTable.php endpoint to execute arbitrary JavaScript in victim's browser.
- Affected versions
-
max 1.7.8.
- Status
-
vulnerable
Mar 29, 2026
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-25339
- CVE, Research URL
- Date
- Mar 25, 2026
- Research Description
- Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Retrieve Embedded Sensitive Data.This issue affects Contact Form by WPForms: from n/a through <= 1.9.8.7.
- Affected versions
-
max 1.9.9.2.
- Status
-
vulnerable
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-32446
- CVE, Research URL
- Date
- Mar 14, 2026
- Research Description
- Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through <= 1.9.9.3.
- Affected versions
-
max 1.9.9.4.
- Status
-
vulnerable
Jun 02, 2026
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-48835
- CVE, Research URL
- Date
- Jun 16, 2026
- Research Description
- Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
- Affected versions
-
max 1.10.0.5.
- Status
-
vulnerable
Jun 06, 2026
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-7792
- CVE, Research URL
- Date
- Jun 06, 2026
- Research Description
- The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to and including 1.10.0.1. This is due to the PayPal Commerce webhook endpoint processing unauthenticated JSON webhook payloads without verifying that the request originated from PayPal using the required HMAC-SHA256 webhook signature, and only checking whether the supplied event_type is whitelisted before dispatching the attacker-controlled resource data to handlers that update payment records. This makes it possible for unauthenticated attackers who know a valid PayPal subscription_id to forge PayPal webhook events and modify subscription payment records, such as reactivating a cancelled or suspended subscription by setting its subscription_status to active.
- Affected versions
-
max 1.10.0.5.
- Status
-
vulnerable
Jun 11, 2026
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-4986
- CVE, Research URL
- Date
- Jun 09, 2026
- Research Description
- The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.
- Affected versions
-
max 1.10.0.5.
- Status
-
vulnerable
Jun 13, 2026
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-40764
- CVE, Research URL
- Date
- Apr 15, 2026
- Research Description
- Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Request Forgery.This issue affects Contact Form by WPForms: from n/a through <= 1.10.0.2.
- Affected versions
-
max 1.10.0.3.
- Status
-
vulnerable
Jun 16, 2026
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 1da2940722f48d1690d6dd8e27da295463f1d8f1
- CVE, Research URL
- Date
- Jul 01, 2020
- Research Description
- WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.6.0.2 WordPress Contact Form by WPForms plugin <= 1.6.0.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Fortinet in WordPress Contact Form by WPForms plugin (versions <= 1.6.0.1).
- Affected versions
-
max 1.6.0.2.
- Status
-
vulnerable
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # e825513b16cdeeb729049311235d0b3a6a84d74e
- CVE, Research URL
- Date
- Dec 10, 2018
- Research Description
- WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.4.8.1 WordPress Contact Form by WPForms plugin <= 1.4.8 - Unauthenticated Cross-Site Scripting (XSS) vulnerability Unauthenticated Cross-Site Scripting (XSS) vulnerability found by RIPS Technologies in WordPress Contact Form by WPForms plugin (versions <= 1.4.8).
- Affected versions
-
max 1.4.8.1.
- Status
-
vulnerable
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 4e6b0bd914c4b285602ff12e2e92b0ae082d841e
- CVE, Research URL
- Date
- Sep 19, 2022
- Research Description
- WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.7.5.5 Contact Form by WPForms <= 1.7.5.3 - Authenticated (Administrator+) Arbitrary File Access via Path Traversal The Contact Form by WPForms plugin for WordPress is vulnerable to Directory Traversal via email template paths in versions up to, and including, 1.7.5.3. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- Affected versions
-
max 1.7.5.5.
- Status
-
vulnerable
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 968181b8559f062008e22f59da5ad30471dec097
- CVE, Research URL
- Date
- Sep 18, 2018
- Research Description
- WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.4.8 Contact Form by WPForms – Drag & Drop Form Builder for WordPress <= 1.4.7.2 - Stored Cross-Site Scripting The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tab parameter in versions up to, and including 1.4.7. This makes it possible for lower-privileged attackers to inject arbitrary web scripts in administrative pages that execute whenever a user accesses the page with the stored web scripts.
- Affected versions
-
max 1.4.8.
- Status
-
vulnerable
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # faa56a23-66bc-4dd7-a5b0-81ea6365d75a
- CVE, Research URL
- Date
- -
- Research Description
- WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.7.5.5 Contact Form by WPForms < 1.7.5.5 - Admin+ Arbitrary File Access The plugin does not validate email template paths, which could allow high privilege users such as admin (for example in multisite) to access arbitrary files on the web server via a path traversal attack
- Affected versions
-
max 1.7.5.5.
- Status
-
vulnerable
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # d973f3d44cf250923d766768efbe28a28351af29
- CVE, Research URL
- Date
- Dec 07, 2018
- Research Description
- WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.4.8 WordPress Contact Form by WPForms plugin <= 1.4.7 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by RIPS Technologies in WordPress Contact Form by WPForms plugin (versions <= 1.4.7).
- Affected versions
-
max 1.4.8.
- Status
-
vulnerable
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 8ce83a5d41d591c8bf4b14bcec65c12d6a288dbf
- CVE, Research URL
- Date
- May 21, 2020
- Research Description
- WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.6.0.2 Contact Form by WPForms <= 1.6.0.1 - Cross-Site Scripting The Contact Form by WPForms plugin for WordPress has a Cross-Site Scripting vulnerability, which is caused by improper input sanitization of user input via the choice label parameter in versions up to, and including, 1.6.0.1.
- Affected versions
-
max 1.6.0.2.
- Status
-
vulnerable
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 3406a1ddccf3a7ae72c59d8e356a958cadcb9a69
- CVE, Research URL
- Date
- Sep 19, 2022
- Research Description
- WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.7.5.5 WordPress Contact Form by WPForms plugin <= 1.7.5.3 - Authenticated Arbitrary File Access vulnerability Authenticated Arbitrary File Access vulnerability discovered by Sybre Waaijer in WordPress Contact Form by WPForms plugin (versions <= 1.7.5.3). Update the WordPress Contact Form by WPForms plugin to the latest available version (at least 1.7.5.5).
- Affected versions
-
max 1.7.5.5.
- Status
-
vulnerable
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 008f8eb8-0643-4e59-bd29-acdc1e6f7a06
- CVE, Research URL
- Date
- -
- Research Description
- WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.4.8.1 Contact Form by WPForms < 1.4.8.1 - Unauthenticated Cross-Site Scripting (XSS) RIPS Technologies identified an Unauthenticated Cross-Site Scripting (XSS) vulnerability within the WPForms WordPress plugin during their WordPress Security Calendar 2018 research. The date parameter was embedded within JavaScript code without any validation or encoding.
- Affected versions
-
max 1.4.8.1.
- Status
-
vulnerable
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 472faeed5471b9fc2cf3a706a38bca2881852640
- CVE, Research URL
- Date
- Dec 10, 2018
- Research Description
- WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More [wpforms-lite] < 1.4.8.1 Contact Form by WPForms <= 1.4.8 - Reflected Cross-Site Scripting The Contact Form by WPForms for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 1.4.8.1.
- Status
-
vulnerable
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 006047c3-2d46-4075-91fe-b55f4b7a4b06
- CVE, Research URL
- Date
- -
- Research Description
- WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.6.0.2 Contact Form by WPForms < 1.6.0.2 - Authenticated Stored Cross-Site Scripting (XSS) Vishnupriya Ilango from Fortinet's FortiGuard Labs discovered an authenticated stored Cross-Site Scripting issue via the choice label parameter inside the form builder that interacts with live preview.
- Affected versions
-
max 1.6.0.2.
- Status
-
vulnerable
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 0a50ad3d-6062-47d9-9602-bfded802200d
- CVE, Research URL
- Date
- -
- Research Description
- WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More [wpforms-lite] < 1.4.8 Contact Form by WPForms < 1.4.8 - Authenticated Stored Cross-Site Scripting (XSS) The Contact Form by WPForms – Drag & Drop Form Builder for WordPress WordPress plugin was affected by an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability.
- Affected versions
-
max 1.4.8.
- Status
-
vulnerable
Jul 01, 2026
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-12127
- CVE, Research URL
- Date
- Jul 01, 2026
- Research Description
- The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 1.10.2 This is due to `get_reply_to_address()` processing the Reply-To display name through smart-tag expansion with context `'notification'` instead of `'notification-reply-to'`, which bypasses email-address validation while `wpforms_sanitize_textarea_field()` intentionally preserves CR/LF characters that are never stripped before the display name is concatenated into the raw `Reply-To:` mail header string. This makes it possible for unauthenticated attackers to inject arbitrary additional email headers — such as `Bcc:` — into outgoing notification emails, silently blind-copying all notification email copies to an attacker-controlled address. Exploitation requires that a form notification is configured to use a Paragraph Text (textarea) field as the Reply-To display name via a Smart Tag.
- Affected versions
-
max 1.10.2.1.
- Status
-
vulnerable
Jul 22, 2026
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-15782
- CVE, Research URL
- Date
- Jul 21, 2026
- Research Description
- The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the OptinMonster plugin to be installed and configured with an active inline campaign that outputs matching #om-{id} markup on the target page, as the WPForms handler only fires when OptinMonster emits its 'om.Campaign.load' event.
- Affected versions
-
max 2.0.0.2.
- Status
-
vulnerable
Sep 26, 2026
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-74991
- CVE, Research URL
- Date
- Sep 24, 2026
- Research Description
- The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to trigger a full refund and an immediate subscription cancellation against payments created by other applications on the site owner's Stripe account.
- Affected versions
-
Min 1.8.8.2, max 2.0.2.
- Status
-
vulnerable
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-88996
- CVE, Research URL
- Date
- Sep 25, 2026
- Research Description
- The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'page_title' POST Parameter via {page_title} Smart Tag in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This is only exploitable on forms whose admin-authored confirmation message places the {page_title} Smart Tag inside an HTML attribute context.
- Affected versions
-
max 2.0.2.1.
- Status
-
vulnerable
Sep 30, 2026
Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-84744
- CVE, Research URL
- Date
- Sep 28, 2026
- Research Description
- The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts.
- Affected versions
-
Min 1.5.0.1, max 2.0.2.1.
- Status
-
vulnerable