{"error":0,"message":null,"data":{"name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More","plugin":"wpforms-lite","link":"https:\/\/wordpress.org\/plugins\/wpforms-lite\/","latest":"1789649700","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"509403639e577df1fd4fd0e1f43bd9a5e9c916da6482a666f10dc6513350a510","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.5.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-10385","name":"CVE-2020-10385","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-10385","description":"[en] A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.","date":"2020-03-11"},{"id":"f5da3daa82410cf18c8cb85d7754ef30f14b02d1","name":"WordPress Contact Form by WPForms plugin <= 1.5.8.2 - Authenticated Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforms-lite\/vulnerability\/wordpress-contact-form-by-wpforms-plugin-1-5-8-2-authenticated-cross-site-scripting-xss-vulnerability","description":"Authenticated Cross-Site Scripting (XSS) vulnerability discovered by Jinson Varghese Behanan in WordPress Contact Form by WPForms plugin (versions <= 1.5.8.2).","date":"2020-03-05"},{"id":"10a8ab25b7940b103ed05a09fc1f1408d4db9eec","name":"Contact Form by WPForms <= 1.5.8.2 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/contact-form-by-wpforms-1582-stored-cross-site-scripting","description":"A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.","date":"2020-02-18"},{"id":"0d5c51d8-a834-4680-9939-b6d37fd3d237","name":"Contact Form by WPForms &lt; 1.5.9 - Authenticated Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/0d5c51d8-a834-4680-9939-b6d37fd3d237","description":"The popular WordPress plugin, WPForms, was found to be vulnerable to Authenticated Cross-Site Scripting (XSS).\r\n\r\nThe Form Description and Field Description fields in the WPForms plugin&rsquo;s Form Builder module was found to be vulnerable to stored XSS, as they did not sanitize user given input properly.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"78cd6fde3ee02e976283ff1272b53694ccde44174c59a6add23c24482a8a9bff","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.6.0.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.6.0.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"1da2940722f48d1690d6dd8e27da295463f1d8f1","name":"WordPress Contact Form by WPForms plugin <= 1.6.0.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforms-lite\/vulnerability\/wordpress-contact-form-by-wpforms-plugin-1-6-0-1-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Fortinet in WordPress Contact Form by WPForms plugin (versions <= 1.6.0.1).","date":"2020-07-01"}],"impact":[]},{"uuid":"9841f281bc2b6fccd95dcbcbd9f4266ce4c7a50e7aff3e08f3e687754c09b851","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.4.8.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.8.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"e825513b16cdeeb729049311235d0b3a6a84d74e","name":"WordPress Contact Form by WPForms plugin <= 1.4.8 - Unauthenticated Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforms-lite\/vulnerability\/wordpress-contact-form-by-wpforms-plugin-1-4-8-unauthenticated-cross-site-scripting-xss-vulnerability","description":"Unauthenticated Cross-Site Scripting (XSS) vulnerability found by RIPS Technologies in WordPress Contact Form by WPForms plugin (versions <= 1.4.8).","date":"2018-12-10"}],"impact":[]},{"uuid":"d363ba651db30ec8ffeabf5780aaa42c8386ac6cd4d946765e360c17298873e0","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.4.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"d973f3d44cf250923d766768efbe28a28351af29","name":"WordPress Contact Form by WPForms plugin <= 1.4.7 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforms-lite\/vulnerability\/wordpress-contact-form-by-wpforms-plugin-1-4-7-authenticated-stored-cross-site-scripting-xss-vulnerability","description":"Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by RIPS Technologies in WordPress Contact Form by WPForms plugin (versions <= 1.4.7).","date":"2018-12-07"}],"impact":[]},{"uuid":"2c98b88dfcabc0794e7a8d8e4be0b1f3d8a88fe8ca554b43aee4bff41e9cb999","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.7.5.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.7.5.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"3406a1ddccf3a7ae72c59d8e356a958cadcb9a69","name":"WordPress Contact Form by WPForms plugin <= 1.7.5.3 - Authenticated Arbitrary File Access vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforms-lite\/vulnerability\/wordpress-contact-form-by-wpforms-plugin-1-7-5-3-authenticated-arbitrary-file-access-vulnerability","description":"Authenticated Arbitrary File Access vulnerability discovered by Sybre Waaijer in WordPress Contact Form by WPForms plugin (versions <= 1.7.5.3).\nUpdate the WordPress Contact Form by WPForms plugin to the latest available version (at least 1.7.5.5).","date":"2022-09-19"}],"impact":[]},{"uuid":"89669cfe12e44dcaf4d50b060ca9503f04974c640904123a5857948bcd0fad88","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.7.5.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.7.5.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4e6b0bd914c4b285602ff12e2e92b0ae082d841e","name":"Contact Form by WPForms <= 1.7.5.3 - Authenticated (Administrator+) Arbitrary File Access via Path Traversal","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/contact-form-by-wpforms-1753-authenticated-administrator-arbitrary-file-access-via-path-traversal","description":"The Contact Form by WPForms plugin for WordPress is vulnerable to Directory Traversal via email template paths in versions up to, and including, 1.7.5.3. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information.","date":"2022-09-19"}],"impact":[]},{"uuid":"4a82883d2f5507434f7737e8083d1fecc7f3cb923dfdf3ccf9ba9a88a481c14b","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.6.0.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.6.0.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"8ce83a5d41d591c8bf4b14bcec65c12d6a288dbf","name":"Contact Form by WPForms <= 1.6.0.1 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/contact-form-by-wpforms-1601-cross-site-scripting","description":"The Contact Form by WPForms plugin for WordPress has a Cross-Site Scripting vulnerability, which is caused by improper input sanitization of user input via the choice label parameter in versions up to, and including, 1.6.0.1.","date":"2020-05-21"}],"impact":[]},{"uuid":"5915ef436117b88b023a7202f19b3a8b05c0a271d4105dea51c876d252431714","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.4.8.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.8.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"472faeed5471b9fc2cf3a706a38bca2881852640","name":"Contact Form by WPForms <= 1.4.8 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/contact-form-by-wpforms-148-reflected-cross-site-scripting","description":"The Contact Form by WPForms for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2018-12-10"}],"impact":[]},{"uuid":"f204757c4c2ba3aea71e60a388204d3423f816c4d3213fbadb46d49ba2230136","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.4.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"968181b8559f062008e22f59da5ad30471dec097","name":"Contact Form by WPForms \u2013 Drag & Drop Form Builder for WordPress <= 1.4.7.2 - Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/contact-form-by-wpforms-drag-drop-form-builder-for-wordpress-1472-stored-cross-site-scripting","description":"The Contact Form by WPForms \u2013 Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tab parameter in versions up to, and including 1.4.7. This makes it possible for lower-privileged attackers to inject arbitrary web scripts in administrative pages that execute whenever a user accesses the page with the stored web scripts.","date":"2018-09-18"}],"impact":[]},{"uuid":"b7098f42c00485a8df4e614964d53e626794f0bfb9ea2dbcff029ae01760a0bc","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.8.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-30500","name":"CVE-2023-30500","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-30500","description":"[en] Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <=\u00a01.8.1.2 versions.","date":"2023-06-22"},{"id":"a82600cb75b0285adf75c5dd7018c26eb27618ea","name":"WordPress  Contact Form by WPForms Plugin  <= 1.8.1.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforms-lite\/vulnerability\/wordpress-wpforms-lite-plugin-1-8-1-2-reflected-cross-site-scripting-xss-vulnerability","description":"Update the WordPress Contact Form by WPForms plugin to the latest available version (at least 1.8.1.3).\nRafie Muhammad (Patchstack) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Contact Form by WPForms Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 1.8.1.3.","date":"2023-06-20"},{"id":"1c63432c7c9ad53e50f86759343b10053bbb8842","name":"Contact Form by WPForms (Free and Premium) <= 1.8.1.2 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/detail\/contact-form-by-wpforms-free-and-premium-1812-reflected-cross-site-scripting","description":"The Contact Form by WPForms (Free and Premium) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.8.1.2 due to insufficient input sanitization and output escaping on debug data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2023-06-20"},{"id":"9a7e7557-0fdb-46d7-97c1-ace6f3e18b9e","name":"Contact Form by WPForms &lt; 1.8.1.3 - Reflected XSS","link":"https:\/\/wpscan.com\/vulnerability\/9a7e7557-0fdb-46d7-97c1-ace6f3e18b9e","description":"The plugin does not sanitise and escape some parameters before outputting them back in the debug page when the WPFORMS_DEBUG constant is defined, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"h","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.8","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"5.8","severity":"medium","av":"network","ac":"high","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"37e21893252a53f596a4ef247614470840567b792b57f591f96b32a5e369728f","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.7.5.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.7.5.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"faa56a23-66bc-4dd7-a5b0-81ea6365d75a","name":"Contact Form by WPForms &lt; 1.7.5.5 - Admin+ Arbitrary File Access","link":"https:\/\/wpscan.com\/vulnerability\/faa56a23-66bc-4dd7-a5b0-81ea6365d75a","description":"The plugin does not validate email template paths, which could allow high privilege users such as admin (for example in multisite) to access arbitrary files on the web server via a path traversal attack","date":null}],"impact":[]},{"uuid":"7f89a659cd44ab8cb34dae306218892531faf08cf502b35c30d75f04cf0701aa","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.6.0.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.6.0.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"006047c3-2d46-4075-91fe-b55f4b7a4b06","name":"Contact Form by WPForms &lt; 1.6.0.2 - Authenticated Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/006047c3-2d46-4075-91fe-b55f4b7a4b06","description":"Vishnupriya Ilango from Fortinet&#039;s FortiGuard Labs discovered an authenticated stored Cross-Site Scripting issue via the choice label parameter inside the form builder that interacts with live preview.","date":null}],"impact":[]},{"uuid":"353a377dfb48e1910c149d479d0d3b4dbc8501a87290571e80f57e2e4d1b9b97","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.4.8.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.8.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"008f8eb8-0643-4e59-bd29-acdc1e6f7a06","name":"Contact Form by WPForms &lt; 1.4.8.1 - Unauthenticated Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/008f8eb8-0643-4e59-bd29-acdc1e6f7a06","description":"RIPS Technologies identified an Unauthenticated Cross-Site Scripting (XSS) vulnerability within the WPForms WordPress plugin during their WordPress Security Calendar 2018 research. The date parameter was embedded within JavaScript code without any validation or encoding.","date":null}],"impact":[]},{"uuid":"ddca6e03fed8fac56f05c7309e289679da3371812e85862d74584eba8089c67e","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.4.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.4.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0a50ad3d-6062-47d9-9602-bfded802200d","name":"Contact Form by WPForms &lt; 1.4.8 - Authenticated Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/0a50ad3d-6062-47d9-9602-bfded802200d","description":"The Contact Form by WPForms &ndash; Drag &amp; Drop Form Builder for WordPress WordPress plugin was affected by an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"85e38a7e20eef14b1746902ff6385aa69a9e85eef4fec94a0f4ae8458794cb53","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.8.8.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.8.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3649","name":"CVE-2024-3649","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3649","description":"[en] The Contact Form by WPForms \u2013 Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to price manipulation in versions up to, and including, 1.8.7.2. This is due to a lack of controls on several product parameters. This makes it possible for unauthenticated attackers to manipulate prices, product information, and quantities for purchases made via the Stripe payment integration.","date":"2024-05-02"},{"id":"df63a778fd57172b68738a94fcbabf0d03fd5a80","name":"Contact Form by WPForms \u2013 Drag & Drop Form Builder for WordPress <= 1.8.7.2 - Unauthenticated Price Manipulation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/contact-form-by-wpforms-drag-drop-form-builder-for-wordpress-1872-unauthenticated-price-manipulation","description":"The Contact Form by WPForms \u2013 Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to price manipulation in versions up to, and including, 1.8.7.2. This is due to a lack of controls on several product parameters. This makes it possible for unauthenticated attackers to manipulate prices, product information, and quantities for purchases made via the Stripe payment integration.","date":"2024-05-01"},{"id":"c7c50eb45b86fd81dfacc67d4fe140d1b7ac5c21","name":"WordPress Contact Form by WPForms Plugin <= 1.8.7.2 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforms-lite\/vulnerability\/wordpress-contact-form-by-wpforms-plugin-1-8-7-2-unauthenticated-price-manipulation-vulnerability","description":"<p>WordPress Contact Form by WPForms Plugin <= 1.8.7.2 is vulnerable to Broken Access Control<\/p><p>Software: Contact Form by WPForms<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wpforms-lite\/#developers<\/p><p>Affected Version <= 1.8.7.2<\/p><p>Fixed in version 1.8.8.2 <\/p>","date":"2024-05-02"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-472","name":"External Control of Assumed-Immutable Web Parameter","description":"The web application does not sufficiently verify inputs that are assumed to be immutable but are actually externally controllable, such as hidden form fields."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b8750e9c757a6fbf143051fdd375765533f5fcf5e4021db315c42523e6277d20","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.9.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-10593","name":"CVE-2024-10593","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-10593","description":"[en] The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.1.6. This is due to missing or incorrect nonce validation on the process_admin_ui function. This makes it possible for unauthenticated attackers to delete WPForm logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-11-13"},{"id":"7031adce8efedc00e314948b2681a2a981b492e7","name":"WordPress Contact Form by WPForms Plugin <= 1.9.1.6 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforms-lite\/vulnerability\/wordpress-wpforms-easy-form-builder-for-wordpress-plugin-1-9-1-6-cross-site-request-forgery-csrf-to-plugin-s-log-deletion-vulnerability","description":"<p>WordPress Contact Form by WPForms Plugin <= 1.9.1.6 is vulnerable to Cross Site Request Forgery (CSRF)<\/p><p>Software: Contact Form by WPForms<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wpforms-lite\/#developers<\/p><p>Affected Version <= 1.9.1.6<\/p><p>Fixed in version 1.9.2.1 <\/p>","date":"2024-11-12"},{"id":"e758db6f621da5644fb9980b190be58f0b4d0a72","name":"WPForms \u2013 Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/wpforms-easy-form-builder-for-wordpress-1916-cross-site-request-forgery-csrf-to-plugins-log-deletion","description":"The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.1.6. This is due to missing or incorrect nonce validation on the process_admin_ui function. This makes it possible for unauthenticated attackers to delete WPForm logs via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-11-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a932a2545b7ebf6e85f78ae490194169735099f04c2a16f9840dc41a43c78d22","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.9.1.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.1.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-7056","name":"CVE-2024-7056","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-7056","description":"[en] The WPForms  WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"2024-11-25"},{"id":"2892a920470c07a26f756febf5c907ff22264ef6","name":"WPForms <= 1.9.1.5 - Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/wpforms-1915-authenticated-administrator-stored-cross-site-scripting","description":"The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-11-04"},{"id":"6eed4e08b944d4c0a6082389615b859fcfbad980","name":"WordPress Contact Form by WPForms Plugin < 1.9.1.6 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforms-lite\/vulnerability\/wordpress-wpforms-plugin-1-9-1-6-admin-stored-xss-vulnerability","description":"<p>WordPress Contact Form by WPForms Plugin < 1.9.1.6 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Contact Form by WPForms<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wpforms-lite\/#developers<\/p><p>Affected Version < 1.9.1.6<\/p><p>Fixed in version 1.9.1.6 <\/p>","date":"2024-11-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"u","c":"l","i":"l","a":"n","score":"3.5","severity":"l","exploitable":"0.9","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:U\/C:L\/I:L\/A:N","score":"3.5","severity":"low","av":"network","ac":"low","pr":"high","ui":"required","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"0.9","impact":"2.5"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3a422fdc71ec7cd4d4f87e6ccaa89613657eea9a504c9aa6f288abfa70bca049","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] >= 1.8.4 - < 1.9.2.2","description":null,"operator":{"min_version":"1.8.4","min_operator":"ge","max_version":"1.9.2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-11205","name":"CVE-2024-11205","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-11205","description":"[en] The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to refund payments and cancel subscriptions.","date":"2024-12-10"},{"id":"308e53760fd19da4bf267d19340645366f4063fe","name":"WPForms 1.8.4 - 1.9.2.1 - Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/wpforms-184-1921-missing-authorization-to-authenticated-subscriber-payment-refund-and-subscription-cancellation","description":"The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to refund payments and cancel subscriptions.","date":"2024-12-09"},{"id":"fe65734dc3f6df4e7c9782ce358c41eed6663cb0","name":"WordPress Contact Form by WPForms Plugin 1.8.4-1.9.2.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wpforms-lite\/vulnerability\/wordpress-wpforms-plugin-1-8-4-1-9-2-1-missing-authorization-to-authenticated-subscriber-payment-refund-and-subscription-cancellation-vulnerability","description":"<p>WordPress Contact Form by WPForms Plugin 1.8.4-1.9.2.1 is vulnerable to Broken Access Control<\/p><p>Software: Contact Form by WPForms<\/p><p>Fixed in version 1.9.2.2 <\/p><p>Affected Version 1.8.4-1.9.2.1<\/p><p>CVE: CVE-2024-11205<\/p>","date":"2024-12-09"},{"id":"EUVD-2024-34017","name":"EUVD-2024-34017","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-34017","description":"The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to refund payments and cancel subscriptions.","date":"2024-12-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"8ef91e8d3b52509db95a411edc291b60d1ed01c6835f66a6594ce556d3afcf59","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.9.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-11223","name":"CVE-2024-11223","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-11223","description":"[en] The WPForms  WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"2024-12-26"},{"id":"f685aa96606e322b87edab5858ca226cd13dca41","name":"WPForms <= 1.9.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/wpforms-1922-authenticated-admin-stored-cross-site-scripting","description":"The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2024-12-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"n","s":"u","c":"l","i":"l","a":"l","score":"4.7","severity":"m","exploitable":"1.2","impact":"3.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:L\/I:L\/A:L","score":"4.7","severity":"medium","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"low","i":"low","a":"low","exploitable":"1.2","impact":"3.4"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"594ccd6c1cfbb3f117fc9c624813ceed19e6ddc1160e8d85b800da6fb5e45d70","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.9.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-56276","name":"CVE-2024-56276","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-56276","description":"[en] Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n\/a through <= 1.9.2.2.","date":"2025-01-07"},{"id":"afe2793768db44b4458085afad27b11a14275a88","name":"Contact Form by WPForms <= 1.9.2.2 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/contact-form-by-wpforms-1922-missing-authorization","description":"The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.9.2.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.","date":"2025-01-03"},{"id":"EUVD-2024-53073","name":"EUVD-2024-53073","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-53073","description":"Missing Authorization vulnerability in WPForms Contact Form by WPForms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n\/a through 1.9.2.2.","date":"2025-01-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"47a1b1d34fb031e43d0aa812fad1466ad63c7d015daf9c4ec008806ed01de427","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.9.3.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.3.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-13403","name":"CVE-2024-13403","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-13403","description":"[en] The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018fieldHTML\u2019 parameter in all versions up to, and including, 1.9.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-02-04"},{"id":"4356199ddbb4895c1c9f62fe0f0777c15ca21687","name":"WPForms Lite <= 1.9.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/wpforms-lite-1931-authenticated-contributor-stored-cross-site-scripting-via-fieldhtml-parameter","description":"The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018fieldHTML\u2019 parameter in all versions up to, and including, 1.9.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-02-03"},{"id":"EUVD-2024-51582","name":"EUVD-2024-51582","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-51582","description":"The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \u2018fieldHTML\u2019 parameter in all versions up to, and including, 1.9.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-02-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"6175bfb5ea501d90eddd194ad2123d6b5a961c1ae784b510590ae9ab9063952a","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.9.5.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.5.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-3794","name":"WPForms Lite <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'start_timestamp' Parameter","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-3794","description":"The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the start_timestamp parameter in all versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"720a898b1b095d72a2e25951eaa4838f79e6fe56","name":"WPForms Lite <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'start_timestamp' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/wpforms-lite-195-authenticated-contributor-stored-cross-site-scripting-via-start-timestamp-parameter","description":"The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the start_timestamp parameter in all versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-05-09"},{"id":"EUVD-2025-14199","name":"EUVD-2025-14199","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-14199","description":"The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the start_timestamp parameter in all versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-05-09"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"91b69d080015a6c808c1bd1a15eda578ee3761d31351f24ee0bef50ed320ba97","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] == 1.7.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.7.8","max_operator":"eq","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2020-36919","name":"CVE-2020-36919","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-36919","description":"[en] WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attackers can inject malicious scripts through the ListTable.php endpoint to execute arbitrary JavaScript in victim's browser.","date":"2026-01-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4f7a44ada79dfc0e4ba33455cfd410e925476ca5f010383a620f812e8e75a8fd","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.9.9.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.9.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-32446","name":"CVE-2026-32446","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-32446","description":"[en] Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n\/a through <= 1.9.9.3.","date":"2026-03-13"},{"id":"1c30d253912d34280491ca13aae369ec36c6dac5","name":"Contact Form by WPForms <= 1.9.9.3 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/contact-form-by-wpforms-1993-missing-authorization","description":"The Contact Form by WPForms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.9.9.3. This makes it possible for authenticated attackers, with contributor-level access and above, to perform an unauthorized action.","date":"2026-03-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"b37a43d2e084c32236ff1503512b2dcbaf375f6e66f73bb770c26270e22c0576","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.9.9.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.9.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-25339","name":"CVE-2026-25339","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-25339","description":"[en] Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Retrieve Embedded Sensitive Data.This issue affects Contact Form by WPForms: from n\/a through <= 1.9.8.7.","date":"2026-03-25"},{"id":"9950712e600888df20a582a93ca38c36c66e7906","name":"WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More <= 1.9.8.7 - Unauthenticated Sensitive Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/wpforms-easy-form-builder-for-wordpress-contact-forms-payment-forms-surveys-more-1987-unauthenticated-sensitive-information-exposure","description":"The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.8.7. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.","date":"2026-03-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"n","a":"n","score":"6.5","severity":"m","exploitable":"2.8","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"2.8","impact":"3.6"},"cwe":[{"cwe":"CWE-201","name":"Insertion of Sensitive Information Into Sent Data","description":"The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"45add8e98630503ebb249737acf3932d0ce5e6cfb379d10409f261ec39933dff","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.10.0.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.10.0.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-40764","name":"CVE-2026-40764","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-40764","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Request Forgery.This issue affects Contact Form by WPForms: from n\/a through <= 1.10.0.2.","date":"2026-04-15"},{"id":"a75de09f38837e92480f4c397ffc6967fa770266","name":"Contact Form by WPForms <= 1.10.0.2 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/contact-form-by-wpforms-11002-cross-site-request-forgery","description":"The Contact Form by WPForms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.0.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2026-03-31"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"n","score":"8.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:N","score":"8.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"none","exploitable":"0.0","impact":"0.0"},"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c4ccc76aa4378931fbeff0a014afe3f438f010a79f420cf6a6274b2e9c8bcc20","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.10.0.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.10.0.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-48835","name":"CVE-2026-48835","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-48835","description":"[en] Unauthenticated Broken Access Control in Contact Form by WPForms <= 1.10.0.4 versions.","date":"2026-06-15"},{"id":"9a2193804c75178795d3f14b7f0e803eff553207","name":"WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More <= 1.10.0.4 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/aa60f16f-bd25-4b8b-9e3c-0996b9e3de42","description":"The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.10.0.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-05-28"},{"id":"16a3aa57d82cd5d59a9d8599308840058df704c3","name":"WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More <= 1.10.0.4 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/wpforms-easy-form-builder-for-wordpress-contact-forms-payment-forms-surveys-more-11004-missing-authorization","description":"The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.10.0.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-07-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"7.5","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"fa64bbb52c34011c7759a326699b1e58aa89f02e45dd073e84dca2521c99c6b5","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.10.0.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.10.0.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-7792","name":"CVE-2026-7792","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-7792","description":"[en] The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to and including 1.10.0.1. This is due to the PayPal Commerce webhook endpoint processing unauthenticated JSON webhook payloads without verifying that the request originated from PayPal using the required HMAC-SHA256 webhook signature, and only checking whether the supplied event_type is whitelisted before dispatching the attacker-controlled resource data to handlers that update payment records. This makes it possible for unauthenticated attackers who know a valid PayPal subscription_id to forge PayPal webhook events and modify subscription payment records, such as reactivating a cancelled or suspended subscription by setting its subscription_status to active.","date":"2026-06-06"},{"id":"26dd48a6b0ab506f442e0ba454b1dfa74cdf4a78","name":"WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/d5cf5fd2-58c7-42d0-948f-95764647630b","description":"The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to and including 1.10.0.1. This is due to the PayPal Commerce webhook endpoint processing unauthenticated JSON webhook payloads without verifying that the request originated from PayPal using the required HMAC-SHA256 webhook signature, and only checking whether the supplied event_type is whitelisted before dispatching the attacker-controlled resource data to handlers that update payment records. This makes it possible for unauthenticated attackers who know a valid PayPal subscription_id to forge PayPal webhook events and modify subscription payment records, such as reactivating a cancelled or suspended subscription by setting its subscription_status to active.","date":"2026-06-05"},{"id":"fe5cc5d5a66e62956ac685fda8039c4447ef804a","name":"WPForms &lt;= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/wpforms-11004-unauthenticated-insufficient-verification-of-data-authenticity-via-paypal-commerce-webhook-endpoint","description":"The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, &amp; More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to and including 1.10.0.1. This is due to the PayPal Commerce webhook endpoint processing unauthenticated JSON webhook payloads without verifying that the request originated from PayPal using the required HMAC-SHA256 webhook signature, and only checking whether the supplied event_type is whitelisted before dispatching the attacker-controlled resource data to handlers that update payment records. This makes it possible for unauthenticated attackers who know a valid PayPal subscription_id to forge PayPal webhook events and modify subscription payment records, such as reactivating a cancelled or suspended subscription by setting its subscription_status to active.","date":null},{"id":"EUVD-2026-34954","name":"EUVD-2026-34954","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-34954","description":"The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to and including 1.10.0.1. This is due to the PayPal Commerce webhook endpoint processing unauthenticated JSON webhook payloads without verifying that the request originated from PayPal using the required HMAC-SHA256 webhook signature, and only checking whether the supplied event_type is whitelisted before dispatching the attacker-controlled resource data to handlers that update payment records. This makes it possible for unauthenticated attackers who know a valid PayPal subscription_id to forge PayPal webhook events and modify subscription payment records, such as reactivating a cancelled or suspended subscription by setting its subscription_status to active.","date":"2026-06-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-345","name":"Insufficient Verification of Data Authenticity","description":"The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"99bcbe3c8eb1374b210c379732f2559bc236a64d08e1d51772d3fc44763a0066","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.10.0.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.10.0.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-4986","name":"CVE-2026-4986","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-4986","description":"[en] The WPForms  WordPress plugin before 1.10.0.5 does not verify the authenticity of incoming PayPal webhook events before processing them, allowing unauthenticated attackers to forge webhook payloads and manipulate the payment state of arbitrary transactions.","date":"2026-06-09"}],"impact":{"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"17f1284cd383d912164d15aa8a15b8c0ecca8e512484b9f339f1f6c20e5d139c","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 1.10.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.10.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-12127","name":"CVE-2026-12127","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-12127","description":"[en] The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 1.10.2 This is due to `get_reply_to_address()` processing the Reply-To display name through smart-tag expansion with context `'notification'` instead of `'notification-reply-to'`, which bypasses email-address validation while `wpforms_sanitize_textarea_field()` intentionally preserves CR\/LF characters that are never stripped before the display name is concatenated into the raw `Reply-To:` mail header string. This makes it possible for unauthenticated attackers to inject arbitrary additional email headers \u2014 such as `Bcc:` \u2014 into outgoing notification emails, silently blind-copying all notification email copies to an attacker-controlled address. Exploitation requires that a form notification is configured to use a Paragraph Text (textarea) field as the Reply-To display name via a Smart Tag.","date":"2026-07-01"},{"id":"699cb622824247811ee669ff2a2bc36a21c7a046","name":"WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/wpforms-1102-improper-neutralization-of-crlf-sequences-to-unauthenticated-email-header-injection-via-reply-to-display-name","description":"The WPForms \u2013 Easy Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 1.10.2 This is due to `get_reply_to_address()` processing the Reply-To display name through smart-tag expansion with context `'notification'` instead of `'notification-reply-to'`, which bypasses email-address validation while `wpforms_sanitize_textarea_field()` intentionally preserves CR\/LF characters that are never stripped before the display name is concatenated into the raw `Reply-To:` mail header string. This makes it possible for unauthenticated attackers to inject arbitrary additional email headers \u2014 such as `Bcc:` \u2014 into outgoing notification emails, silently blind-copying all notification email copies to an attacker-controlled address. Exploitation requires that a form notification is configured to use a Paragraph Text (textarea) field as the Reply-To display name via a Smart Tag.","date":"2026-06-30"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-93","name":"Improper Neutralization of CRLF Sequences ('CRLF Injection')","description":"The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a0f99be9b8d5e06d037e72bffd5b4989c8850dab82d6f440694b78acecf52a7d","name":"WPForms &#8211; AI Form Builder for WordPress &#8211; Contact Forms, Payment Forms, Survey Form, Quiz &amp; More [wpforms-lite] < 2.0.0.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.0.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-15782","name":"CVE-2026-15782","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15782","description":"[en] The WPForms \u2013 AI Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the OptinMonster plugin to be installed and configured with an active inline campaign that outputs matching #om-{id} markup on the target page, as the WPForms handler only fires when OptinMonster emits its 'om.Campaign.load' event.","date":"2026-07-21"},{"id":"f3a1678fa2f148a2765aa242a4de230771dac35c","name":"WPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wpforms-lite\/wpforms-2001-authenticated-contributor-stored-cross-site-scripting-via-optinmonster-integration-data-sitekey-attribute-in-post-content","description":"The WPForms \u2013 AI Form Builder for WordPress \u2013 Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions up to, and including, 2.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the OptinMonster plugin to be installed and configured with an active inline campaign that outputs matching #om-{id} markup on the target page, as the WPForms handler only fires when OptinMonster emits its 'om.Campaign.load' event.","date":"2026-07-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"h","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"4.9","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"4.9","severity":"medium","av":"network","ac":"high","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}],"supplychain":[{"verdict":"suspicious","audit_id":52,"affected_versions":{"min_version":"1.10.2.1","min_operator":"ge","max_version":null,"max_operator":null},"baseline_version":"1.10.2.1","head_version":"2.0.0.3","ioc_count":0,"closed_by_wporg":false,"c2_infrastructure":[],"signals":[],"wpbeacon_url":"https:\/\/wpbeacon.io\/audits\/52\/","published_at":"2026-08-11"}]},"updated":"1788295741"}