📦 Wpforms

by Wpforms

🔍 What is Wpforms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-11205

HIGH CVSS 8.5 Dec 10, 2024

This vulnerability in the WPForms WordPress plugin allows authenticated users with Subscriber-level access or higher to refund payments and cancel subscriptions without proper authorization. It affect...

CVE-2023-7063

HIGH CVSS 7.2 Jan 20, 2024

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using WPForms Pro plugin. When users visit pages containing these injected forms, the scripts execu...

CVE-2024-13403

MEDIUM CVSS 6.4 Feb 4, 2025

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to inject malicious JavaScript into WPForms plugin pages. The injected scripts execute whenever other us...

CVE-2024-56276

MEDIUM CVSS 4.3 Jan 7, 2025

This CVE describes a missing authorization vulnerability in WPForms Contact Form plugin that allows attackers to bypass access controls and perform unauthorized actions. It affects all WordPress sites...

CVE-2024-11223

MEDIUM CVSS 4.7 Dec 26, 2024

This vulnerability in the WPForms WordPress plugin allows administrators to inject malicious scripts into plugin settings, which then execute in other users' browsers. It affects WordPress sites using...