← WordPress Vulnerabilities
WordPress security by component

Contact Form by WPForms – Drag & Drop Form Builder for

Contact Form by WPForms – Drag & Drop Form Builder for is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published May 02, 2024; the highest published CVSS base score is 5.3.

Plugin slug: contact-form-by-wpforms-drag-drop-form-builder-for-wordpress

CVE-2024-3649: Contact Form by WPForms – Drag & Drop Form Builder for: A security weakness

Contact Form by WPForms – Drag & Drop Form Builder for is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedMay 02, 2024
Safe version guidanceSee mitigation notes
Published vulnerabilities for contact-form-by-wpforms-drag-drop-form-builder-for-wordpress
Safe version
May 02, 2024 CVE-2024-3649
Contact Form by WPForms – Drag & Drop Form Builder for: A security weakness
Contact Form by WPForms – Drag & Drop Form Builder for is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE5.3
NVDPending