← WordPress Vulnerabilities
WordPress security by component

Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms

Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 10, 2026; the highest CVE/CNA score is 6.6.

Plugin slug: for-wordpress-drag-drop-contact-forms-surveys-payments-multipurpose-forms

CVE-2025-11977: Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms: Filesystem traversal

Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms is affected by filesystem traversal. Exploitation requires at least administrator-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 1.26.12.

PublishedJul 10, 2026
Known safe version> 1.26.12
Safe version
Jul 10, 2026 CVE-2025-11977
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms: Filesystem traversal
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms is affected by filesystem traversal. Exploitation requires at least administrator-level access. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 1.26.12.
> 1.26.12
CVE6.6
NVDPending