Wpforms

Wpforms

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Veröffentlicht 04.02.2025 09:15:09
  • Zuletzt bearbeitet 12.08.2025 16:38:49

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fieldHTML’ parameter in all versions up to, and including, 1.9.3.1 due to insuffi...

  • EPSS 0.26%
  • Veröffentlicht 07.01.2025 11:15:09
  • Zuletzt bearbeitet 12.08.2025 18:49:02

Missing Authorization vulnerability in WPForms Contact Form by WPForms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through 1.9.2.2.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 26.12.2024 06:15:05
  • Zuletzt bearbeitet 08.05.2025 19:46:24

The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed...

  • EPSS 0.2%
  • Veröffentlicht 10.12.2024 05:15:05
  • Zuletzt bearbeitet 12.08.2025 19:06:58

The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for au...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 25.11.2024 06:15:07
  • Zuletzt bearbeitet 15.05.2025 15:06:57

The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed...

  • EPSS 0.06%
  • Veröffentlicht 13.11.2024 03:15:04
  • Zuletzt bearbeitet 10.07.2025 16:34:34

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.1.6. This is due to missing or incorrect nonce va...

  • EPSS 1.38%
  • Veröffentlicht 20.01.2024 09:15:07
  • Zuletzt bearbeitet 30.05.2025 15:15:28

The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including, 1.8.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unau...

  • EPSS 0.1%
  • Veröffentlicht 22.06.2023 12:15:11
  • Zuletzt bearbeitet 21.11.2024 08:00:18

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 versions.