📦 Weforms

by Weformspro

🔍 What is Weforms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-22276

CRITICAL CVSS 9.8 Nov 4, 2020

CVE-2020-22276 is a CSV injection vulnerability in the WeForms WordPress plugin version 1.4.7 that allows attackers to inject malicious formulas into exported CSV files. When administrators export for...

CVE-2024-0386

HIGH CVSS 7.2 Mar 12, 2024

The weForms WordPress plugin has a stored XSS vulnerability in versions up to 1.6.21 where attackers can inject malicious scripts via the 'Referer' HTTP header. These scripts execute when users view a...

CVE-2023-51524

MEDIUM CVSS 4.3 Jun 12, 2024

CVE-2023-51524 is a missing authorization vulnerability in the weForms WordPress plugin that allows unauthorized users to access form submission data and potentially modify form settings. This affects...