Home/Product/wpforms
Product

wpforms

15 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2020-36919
<= 1.7.8
WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attackers can i
6.1MEDIUM
CVE-2024-11273
< 2.6.0
The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its
6.1MEDIUM
CVE-2024-11272
< 2.6.0
The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its
6.1MEDIUM
CVE-2024-13403
< 1.9.3.2
The WPForms - Easy Form Builder for WordPress - Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable t
6.4MEDIUM
CVE-2024-56276
< 1.9.2.3
Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Configured A
4.3MEDIUM
CVE-2024-11223
< 1.9.2.3
The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege u
4.7MEDIUM
CVE-2024-11205
>= 1.8.4 and < 1.9.2.2
The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpfo
8.5HIGH
CVE-2024-7056
< 1.9.1.6
The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege u
3.5LOW
CVE-2024-10593
< 1.9.2.1
The WPForms - Easy Form Builder for WordPress - Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable t
4.3MEDIUM
CVE-2023-7063
<= 1.8.5.3
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions u
7.2HIGH
CVE-2023-3213
<= 3.8.0
The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is
5.3MEDIUM
CVE-2023-30500
<= 1.8.1.2
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms Lite (wpforms-lite), WPForms Pro (wpforms) p
5.8MEDIUM
CVE-2019-25145
<= 2.5.1
The Contact Form & SMTP Plugin by PirateForms plugin for WordPress is vulnerable to HTML injection in the ‘public/class-piratefo
7.2HIGH
CVE-2022-3574
< 1.7.7
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead t
9.8CRITICAL
CVE-2020-10385
< 1.5.9
A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for Wo
5.4MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin