WordPress security by component
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More
Plugin description
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More is a WordPress component with 14 published CVE records in this archive. The latest tracked vulnerability was published Jul 21, 2026; the highest CVE/CNA score is 8.5.
Plugin slug:
wpforms-liteLatest vulnerability
CVE-2026-15782: WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More: Cross-site scripting
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.0.0.1.
| Safe version |
|
||
|---|---|---|---|
| Jul 21, 2026 |
CVE-2026-15782
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More: Cross-site scripting
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.0.0.1.
|
> 2.0.0.1 |
CVE4.9
NVDPending
|
| Jul 01, 2026 |
CVE-2026-12127
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More: A security weakness
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.10.2.
|
> 1.10.2 |
CVE5.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-48835
Contact Form by WPForms: A security weakness
Contact Form by WPForms is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 1.10.0.4.
|
1.10.0.5 |
CVE7.5
NVDPending
|
| Jun 06, 2026 |
CVE-2026-7792
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More: A security weakness
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.10.0.4.
|
> 1.10.0.4 |
CVE5.3
NVDPending
|
| Apr 15, 2026 |
CVE-2026-40764
Contact Form by WPForms: Cross-site request forgery
Contact Form by WPForms is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 1.10.0.2.
|
1.10.0.3 |
CVE8.1
NVDPending
|
| Mar 25, 2026 |
CVE-2026-25339
Contact Form by WPForms: A security weakness
Contact Form by WPForms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.9.8.7.
|
1.9.9.2 |
CVE6.5
NVDPending
|
| Mar 13, 2026 |
CVE-2026-32446
Contact Form by WPForms: A security weakness
Contact Form by WPForms is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jan 13, 2026 |
CVE-2020-36919
Wpforms Lite: Cross-site scripting
Wpforms Lite is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.1
NVDPending
|
| May 09, 2025 |
CVE-2025-3794
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More: Cross-site scripting
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Feb 04, 2025 |
CVE-2024-13403
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More: Cross-site scripting
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Dec 10, 2024 |
CVE-2024-11205
WPForms: A security weakness
WPForms is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.5
NVD6.5
|
| Nov 13, 2024 |
CVE-2024-10593
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More: Cross-site request forgery
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 22, 2023 |
CVE-2023-30500
Wpforms Lite: Cross-site scripting
Wpforms Lite is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.8
NVD6.1
|
| Mar 24, 2020 |
CVE-2020-10385
Wpforms Lite: Cross-site scripting
Wpforms Lite is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|