cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwpforms-lite wpforms-lite

Direction: descending
Sep 30, 2026

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-84744

CVE, Research URL

CVE-2026-84744

Date
Sep 28, 2026
Research Description
The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public posts.
Affected versions
Min 1.5.0.1, max 2.0.2.1.
Status
vulnerable
Sep 26, 2026

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-74991

CVE, Research URL

CVE-2026-74991

Date
Sep 24, 2026
Research Description
The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to trigger a full refund and an immediate subscription cancellation against payments created by other applications on the site owner's Stripe account.
Affected versions
Min 1.8.8.2, max 2.0.2.
Status
vulnerable

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-88996

CVE, Research URL

CVE-2026-88996

Date
Sep 25, 2026
Research Description
The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'page_title' POST Parameter via {page_title} Smart Tag in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This is only exploitable on forms whose admin-authored confirmation message places the {page_title} Smart Tag inside an HTML attribute context.
Affected versions
max 2.0.2.1.
Status
vulnerable
Jul 22, 2026

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-15782

CVE, Research URL

CVE-2026-15782

Date
Jul 21, 2026
Research Description
The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the OptinMonster plugin to be installed and configured with an active inline campaign that outputs matching #om-{id} markup on the target page, as the WPForms handler only fires when OptinMonster emits its 'om.Campaign.load' event.
Affected versions
max 2.0.0.2.
Status
vulnerable
Jul 01, 2026

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-12127

CVE, Research URL

CVE-2026-12127

Date
Jul 01, 2026
Research Description
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 1.10.2 This is due to `get_reply_to_address()` processing the Reply-To display name through smart-tag expansion with context `'notification'` instead of `'notification-reply-to'`, which bypasses email-address validation while `wpforms_sanitize_textarea_field()` intentionally preserves CR/LF characters that are never stripped before the display name is concatenated into the raw `Reply-To:` mail header string. This makes it possible for unauthenticated attackers to inject arbitrary additional email headers — such as `Bcc:` — into outgoing notification emails, silently blind-copying all notification email copies to an attacker-controlled address. Exploitation requires that a form notification is configured to use a Paragraph Text (textarea) field as the Reply-To display name via a Smart Tag.
Affected versions
max 1.10.2.1.
Status
vulnerable
Jun 16, 2026

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 1da2940722f48d1690d6dd8e27da295463f1d8f1

Date
Jul 01, 2020
Research Description
WPForms &#8211; Easy Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Surveys, &amp; More [wpforms-lite] < 1.6.0.2 WordPress Contact Form by WPForms plugin <= 1.6.0.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Fortinet in WordPress Contact Form by WPForms plugin (versions <= 1.6.0.1).
Affected versions
max 1.6.0.2.
Status
vulnerable

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # e825513b16cdeeb729049311235d0b3a6a84d74e

Date
Dec 10, 2018
Research Description
WPForms &#8211; Easy Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Surveys, &amp; More [wpforms-lite] < 1.4.8.1 WordPress Contact Form by WPForms plugin <= 1.4.8 - Unauthenticated Cross-Site Scripting (XSS) vulnerability Unauthenticated Cross-Site Scripting (XSS) vulnerability found by RIPS Technologies in WordPress Contact Form by WPForms plugin (versions <= 1.4.8).
Affected versions
max 1.4.8.1.
Status
vulnerable

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 4e6b0bd914c4b285602ff12e2e92b0ae082d841e

Date
Sep 19, 2022
Research Description
WPForms &#8211; Easy Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Surveys, &amp; More [wpforms-lite] < 1.7.5.5 Contact Form by WPForms <= 1.7.5.3 - Authenticated (Administrator+) Arbitrary File Access via Path Traversal The Contact Form by WPForms plugin for WordPress is vulnerable to Directory Traversal via email template paths in versions up to, and including, 1.7.5.3. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected versions
max 1.7.5.5.
Status
vulnerable

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 968181b8559f062008e22f59da5ad30471dec097

Date
Sep 18, 2018
Research Description
WPForms &#8211; Easy Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Surveys, &amp; More [wpforms-lite] < 1.4.8 Contact Form by WPForms – Drag & Drop Form Builder for WordPress <= 1.4.7.2 - Stored Cross-Site Scripting The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tab parameter in versions up to, and including 1.4.7. This makes it possible for lower-privileged attackers to inject arbitrary web scripts in administrative pages that execute whenever a user accesses the page with the stored web scripts.
Affected versions
max 1.4.8.
Status
vulnerable

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # faa56a23-66bc-4dd7-a5b0-81ea6365d75a

Date
-
Research Description
WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.7.5.5 Contact Form by WPForms &lt; 1.7.5.5 - Admin+ Arbitrary File Access The plugin does not validate email template paths, which could allow high privilege users such as admin (for example in multisite) to access arbitrary files on the web server via a path traversal attack
Affected versions
max 1.7.5.5.
Status
vulnerable

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # d973f3d44cf250923d766768efbe28a28351af29

Date
Dec 07, 2018
Research Description
WPForms &#8211; Easy Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Surveys, &amp; More [wpforms-lite] < 1.4.8 WordPress Contact Form by WPForms plugin <= 1.4.7 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by RIPS Technologies in WordPress Contact Form by WPForms plugin (versions <= 1.4.7).
Affected versions
max 1.4.8.
Status
vulnerable

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 8ce83a5d41d591c8bf4b14bcec65c12d6a288dbf

Date
May 21, 2020
Research Description
WPForms &#8211; Easy Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Surveys, &amp; More [wpforms-lite] < 1.6.0.2 Contact Form by WPForms <= 1.6.0.1 - Cross-Site Scripting The Contact Form by WPForms plugin for WordPress has a Cross-Site Scripting vulnerability, which is caused by improper input sanitization of user input via the choice label parameter in versions up to, and including, 1.6.0.1.
Affected versions
max 1.6.0.2.
Status
vulnerable

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 3406a1ddccf3a7ae72c59d8e356a958cadcb9a69

Date
Sep 19, 2022
Research Description
WPForms &#8211; Easy Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Surveys, &amp; More [wpforms-lite] < 1.7.5.5 WordPress Contact Form by WPForms plugin <= 1.7.5.3 - Authenticated Arbitrary File Access vulnerability Authenticated Arbitrary File Access vulnerability discovered by Sybre Waaijer in WordPress Contact Form by WPForms plugin (versions <= 1.7.5.3). Update the WordPress Contact Form by WPForms plugin to the latest available version (at least 1.7.5.5).
Affected versions
max 1.7.5.5.
Status
vulnerable

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 008f8eb8-0643-4e59-bd29-acdc1e6f7a06

Date
-
Research Description
WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.4.8.1 Contact Form by WPForms &lt; 1.4.8.1 - Unauthenticated Cross-Site Scripting (XSS) RIPS Technologies identified an Unauthenticated Cross-Site Scripting (XSS) vulnerability within the WPForms WordPress plugin during their WordPress Security Calendar 2018 research. The date parameter was embedded within JavaScript code without any validation or encoding.
Affected versions
max 1.4.8.1.
Status
vulnerable

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 472faeed5471b9fc2cf3a706a38bca2881852640

Date
Dec 10, 2018
Research Description
WPForms &#8211; Easy Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Surveys, &amp; More [wpforms-lite] < 1.4.8.1 Contact Form by WPForms <= 1.4.8 - Reflected Cross-Site Scripting The Contact Form by WPForms for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 1.4.8.1.
Status
vulnerable

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 006047c3-2d46-4075-91fe-b55f4b7a4b06

Date
-
Research Description
WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.6.0.2 Contact Form by WPForms &lt; 1.6.0.2 - Authenticated Stored Cross-Site Scripting (XSS) Vishnupriya Ilango from Fortinet&#039;s FortiGuard Labs discovered an authenticated stored Cross-Site Scripting issue via the choice label parameter inside the form builder that interacts with live preview.
Affected versions
max 1.6.0.2.
Status
vulnerable

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # 0a50ad3d-6062-47d9-9602-bfded802200d

Date
-
Research Description
WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.4.8 Contact Form by WPForms &lt; 1.4.8 - Authenticated Stored Cross-Site Scripting (XSS) The Contact Form by WPForms &ndash; Drag &amp; Drop Form Builder for WordPress WordPress plugin was affected by an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability.
Affected versions
max 1.4.8.
Status
vulnerable
Jun 13, 2026

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-40764

CVE, Research URL

CVE-2026-40764

Date
Apr 15, 2026
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Request Forgery.This issue affects Contact Form by WPForms: from n/a through <= 1.10.0.2.
Affected versions
max 1.10.0.3.
Status
vulnerable
Jun 11, 2026

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-4986

CVE, Research URL

CVE-2026-4986

Date
Jun 09, 2026
Research Description
The WPForms WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.
Affected versions
max 1.10.0.5.
Status
vulnerable
Jun 06, 2026

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-7792

CVE, Research URL

CVE-2026-7792

Date
Jun 06, 2026
Research Description
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to and including 1.10.0.1. This is due to the PayPal Commerce webhook endpoint processing unauthenticated JSON webhook payloads without verifying that the request originated from PayPal using the required HMAC-SHA256 webhook signature, and only checking whether the supplied event_type is whitelisted before dispatching the attacker-controlled resource data to handlers that update payment records. This makes it possible for unauthenticated attackers who know a valid PayPal subscription_id to forge PayPal webhook events and modify subscription payment records, such as reactivating a cancelled or suspended subscription by setting its subscription_status to active.
Affected versions
max 1.10.0.5.
Status
vulnerable
Jun 02, 2026

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-48835

CVE, Research URL

CVE-2026-48835

Date
Jun 16, 2026
Research Description
Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.
Affected versions
max 1.10.0.5.
Status
vulnerable
Mar 29, 2026

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-25339

CVE, Research URL

CVE-2026-25339

Date
Mar 25, 2026
Research Description
Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Retrieve Embedded Sensitive Data.This issue affects Contact Form by WPForms: from n/a through <= 1.9.8.7.
Affected versions
max 1.9.9.2.
Status
vulnerable

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2026-32446

CVE, Research URL

CVE-2026-32446

Date
Mar 14, 2026
Research Description
Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through <= 1.9.9.3.
Affected versions
max 1.9.9.4.
Status
vulnerable
Jan 27, 2026

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2020-36919

CVE, Research URL

CVE-2020-36919

Date
Jan 14, 2026
Research Description
WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attackers can inject malicious scripts through the ListTable.php endpoint to execute arbitrary JavaScript in victim's browser.
Affected versions
max 1.7.8.
Status
vulnerable
May 10, 2025

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2025-3794

CVE, Research URL

CVE-2025-3794

Date
May 10, 2025
Research Description
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the start_timestamp parameter in all versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.9.5.1.
Status
vulnerable
Feb 05, 2025

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2024-13403

CVE, Research URL

CVE-2024-13403

Date
Feb 04, 2025
Research Description
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fieldHTML’ parameter in all versions up to, and including, 1.9.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 1.9.3.2.
Status
vulnerable
Jan 09, 2025

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2024-56276

CVE, Research URL

CVE-2024-56276

Date
Jan 07, 2025
Research Description
Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through <= 1.9.2.2.
Affected versions
max 1.9.2.3.
Status
vulnerable
Dec 25, 2024

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2024-11223

CVE, Research URL

CVE-2024-11223

Date
Dec 26, 2024
Research Description
The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 1.9.2.3.
Status
vulnerable
Dec 11, 2024

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2024-11205

CVE, Research URL

CVE-2024-11205

Date
Dec 10, 2024
Research Description
The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to refund payments and cancel subscriptions.
Affected versions
Min 1.8.4, max 1.9.2.1.
Status
vulnerable
Nov 20, 2024

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2024-7056

CVE, Research URL

CVE-2024-7056

Date
Nov 25, 2024
Research Description
The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 1.9.1.6.
Status
vulnerable
Nov 13, 2024

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2024-10593

CVE, Research URL

CVE-2024-10593

Date
Nov 13, 2024
Research Description
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.1.6. This is due to missing or incorrect nonce validation on the process_admin_ui function. This makes it possible for unauthenticated attackers to delete WPForm logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 1.9.2.1.
Status
vulnerable
Jun 07, 2024

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2020-10385

CVE, Research URL

CVE-2020-10385

Date
Mar 24, 2020
Research Description
A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.
Affected versions
max 1.5.9.
Status
vulnerable

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2023-30500

CVE, Research URL

CVE-2023-30500

Date
Jun 22, 2023
Research Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 versions.
Affected versions
max 1.8.1.3.
Status
vulnerable

Contact Form by WPForms – Drag & Drop Form Builder for WordPress # CVE-2024-3649

CVE, Research URL

CVE-2024-3649

Date
May 02, 2024
Research Description
The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to price manipulation in versions up to, and including, 1.8.7.2. This is due to a lack of controls on several product parameters. This makes it possible for unauthenticated attackers to manipulate prices, product information, and quantities for purchases made via the Stripe payment integration.
Affected versions
max 1.8.8.2.
Status
vulnerable