WordPress security by component
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder
Plugin description
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder builds contact and custom forms with configurable fields, submissions, notifications, and form management tools in WordPress.
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder (contact-form) is a WordPress plugin with 20 published CVE records in this archive. The latest tracked vulnerability was published Jun 30, 2025; the highest published CVSS base score is 9.8.
Plugin slug:
contact-formLatest vulnerability
CVE-2025-5730: Contact Form Plugin: Cross-site scripting
Contact Form Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
| Safe version |
|
||
|---|---|---|---|
| Jun 30, 2025 |
CVE-2025-5730
Contact Form Plugin: Cross-site scripting
Contact Form Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Mar 25, 2025 |
CVE-2024-11273
Contact Form & SMTP Plugin for WordPress by PirateForms: Cross-site scripting
Contact Form & SMTP Plugin for WordPress by PirateForms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Dec 09, 2024 |
CVE-2024-9651
Fluent Forms: Cross-site scripting
Fluent Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| May 22, 2024 |
CVE-2024-4157
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder: Code execution
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder is affected by code execution. Exploitation requires an authenticated contributor account. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.5
NVD8.8
|
| May 18, 2024 |
CVE-2024-2782
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder: A security weakness
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVDPending
|
| May 18, 2024 |
CVE-2024-2772
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder: Cross-site scripting
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 18, 2024 |
CVE-2024-2771
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder: Privilege escalation or authentication bypass
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Apr 09, 2024 |
CVE-2024-2200
Contact Form by BestWebSoft: Cross-site scripting
Contact Form by BestWebSoft is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Mar 13, 2024 |
CVE-2023-6957
Fluent Forms: Cross-site scripting
Fluent Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.9
NVD5.4
|
| Jan 27, 2024 |
CVE-2024-0618
Contact Form Plugin – Fastest Contact Form Builder: Cross-site scripting
Contact Form Plugin – Fastest Contact Form Builder is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.4
NVD4.8
|
| Jun 07, 2023 |
CVE-2019-25145
Contact Form & SMTP Plugin by PirateForms: A security weakness
Contact Form & SMTP Plugin by PirateForms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Apr 10, 2023 |
CVE-2023-0546
Contact Form Plugin: Cross-site scripting
Contact Form Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Apr 09, 2023 |
CVE-2014-125095
Contact Form: Cross-site scripting
Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE3.5
NVD6.1
|
| Apr 05, 2023 |
CVE-2013-10022
Contact Form: Cross-site scripting
Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE3.5
NVD6.1
|
| Nov 07, 2022 |
CVE-2022-3463
Contact Form Plugin: A security weakness
Contact Form Plugin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Jun 16, 2022 |
CVE-2017-20055
Contact Form: Cross-site scripting
Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE3.5
NVD5.4
|
| Mar 07, 2022 |
CVE-2021-24777
view submission functionality in the Hotscot Contact Form: SQL injection
view submission functionality in the Hotscot Contact Form is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD7.2
|
| Feb 28, 2022 |
CVE-2021-24689
Contact Forms - Drag & Drop Contact Form Builder: Filesystem traversal
Contact Forms - Drag & Drop Contact Form Builder is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVEPending
NVD4.9
|
| Oct 25, 2021 |
CVE-2021-24381
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD4.8
|
| May 05, 2021 |
CVE-2021-24276
Contact Form by Supsystic: Cross-site scripting
Contact Form by Supsystic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|