← WordPress Vulnerabilities
WordPress security by component

Contact Form Plugin

Contact Form Plugin is a WordPress component with 20 published CVE records in this archive. The latest tracked vulnerability was published Jun 30, 2025; the highest CVE/CNA score is 9.8.

Plugin slug: contact-form

CVE-2025-5730: Contact Form Plugin: Cross-site scripting

Contact Form Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedJun 30, 2025
Safe version guidanceSee mitigation notes
Safe version
Jun 30, 2025 CVE-2025-5730
Contact Form Plugin: Cross-site scripting
Contact Form Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVDPending
Mar 25, 2025 CVE-2024-11273
Contact Form & SMTP Plugin for WordPress by PirateForms: Cross-site scripting
Contact Form & SMTP Plugin for WordPress by PirateForms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Dec 09, 2024 CVE-2024-9651
Fluent Forms: Cross-site scripting
Fluent Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
May 22, 2024 CVE-2024-4157
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder: Code execution
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder is affected by code execution. Exploitation requires at least contributor-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.5
NVD8.8
May 18, 2024 CVE-2024-2782
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder: A security weakness
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVDPending
May 18, 2024 CVE-2024-2772
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder: Cross-site scripting
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
May 18, 2024 CVE-2024-2771
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder: Privilege escalation or authentication bypass
Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Apr 09, 2024 CVE-2024-2200
Contact Form by BestWebSoft: Cross-site scripting
Contact Form by BestWebSoft is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVDPending
Mar 13, 2024 CVE-2023-6957
Fluent Forms: Cross-site scripting
Fluent Forms is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.9
NVD5.4
Jan 27, 2024 CVE-2024-0618
Contact Form Plugin – Fastest Contact Form Builder: Cross-site scripting
Contact Form Plugin – Fastest Contact Form Builder is affected by cross-site scripting. Exploitation requires at least administrator-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVD4.8
Jun 07, 2023 CVE-2019-25145
Contact Form & SMTP Plugin by PirateForms: A security weakness
Contact Form & SMTP Plugin by PirateForms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.2
NVD6.1
Apr 10, 2023 CVE-2023-0546
Contact Form Plugin: A security weakness
Contact Form Plugin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.4
Apr 09, 2023 CVE-2014-125095
Contact Form: Cross-site scripting
Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVD6.1
Apr 05, 2023 CVE-2013-10022
Contact Form: Cross-site scripting
Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVD6.1
Nov 07, 2022 CVE-2022-3463
Contact Form Plugin: A security weakness
Contact Form Plugin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD9.8
Jun 16, 2022 CVE-2017-20055
Contact Form: Cross-site scripting
Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE3.5
NVD5.4
Mar 07, 2022 CVE-2021-24777
view submission functionality in the Hotscot Contact Form: SQL injection
view submission functionality in the Hotscot Contact Form is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2
Feb 28, 2022 CVE-2021-24689
Contact Forms - Drag & Drop Contact Form Builder: Filesystem traversal
Contact Forms - Drag & Drop Contact Form Builder is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE4.9
NVD4.9
Oct 25, 2021 CVE-2021-24381
Ninja Forms Contact Form: Cross-site scripting
Ninja Forms Contact Form is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
May 05, 2021 CVE-2021-24276
Contact Form by Supsystic: Cross-site scripting
Contact Form by Supsystic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1