← WordPress Vulnerabilities
WordPress security by component

4ECPS Web Forms

4ECPS Web Forms is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Jan 09, 2025; the highest CVE/CNA score is 10.

Plugin slug: 4ecps-webforms

CVE-2025-22504: 4ECPS Web Forms: Dangerous file upload

4ECPS Web Forms is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.

PublishedJan 09, 2025
Safe version guidanceSee mitigation notes
Safe version
Jan 09, 2025 CVE-2025-22504
4ECPS Web Forms: Dangerous file upload
4ECPS Web Forms is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE10.0
NVDPending
Nov 03, 2022 CVE-2022-44628
4Ecps Webforms: Cross-site scripting
4Ecps Webforms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8