CVE-2024-13403
- EPSS 0.09%
- Veröffentlicht 04.02.2025 09:15:09
- Zuletzt bearbeitet 12.08.2025 16:38:49
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fieldHTML’ parameter in all versions up to, and including, 1.9.3.1 due to insuffi...
CVE-2024-56276
- EPSS 0.26%
- Veröffentlicht 07.01.2025 11:15:09
- Zuletzt bearbeitet 12.08.2025 18:49:02
Missing Authorization vulnerability in WPForms Contact Form by WPForms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through 1.9.2.2.
CVE-2024-11223
- EPSS 0.07%
- Veröffentlicht 26.12.2024 06:15:05
- Zuletzt bearbeitet 08.05.2025 19:46:24
The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed...
CVE-2024-11205
- EPSS 0.2%
- Veröffentlicht 10.12.2024 05:15:05
- Zuletzt bearbeitet 12.08.2025 19:06:58
The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for au...
CVE-2024-7056
- EPSS 0.15%
- Veröffentlicht 25.11.2024 06:15:07
- Zuletzt bearbeitet 15.05.2025 15:06:57
The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed...
CVE-2024-10593
- EPSS 0.06%
- Veröffentlicht 13.11.2024 03:15:04
- Zuletzt bearbeitet 10.07.2025 16:34:34
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.1.6. This is due to missing or incorrect nonce va...
CVE-2023-7063
- EPSS 1.38%
- Veröffentlicht 20.01.2024 09:15:07
- Zuletzt bearbeitet 30.05.2025 15:15:28
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including, 1.8.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unau...
CVE-2023-30500
- EPSS 0.1%
- Veröffentlicht 22.06.2023 12:15:11
- Zuletzt bearbeitet 21.11.2024 08:00:18
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 versions.