Extension WordPress

Vulnérabilités WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin

Cette page rassemble les failles publiées pour WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
1Critiques
5Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin

5 fiches

CVE-2025-49330 Critique · 9,8
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin

Integration for Contact Form 7 and Zoho CRM, Bigin <= 1.3.0 – Unauthenticated PHP Object Injection

The Integration for Contact Form 7 and Zoho CRM, Bigin plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.3.0 via deserialization of untrusted input. This makes it possible for unauthenticated attackers…

Versions affectées

*-1.3.0

Correctif

1.3.1

Publication

16/06/2025

CVE-2023-2527 Élevée · 7,2
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin

Integration for Contact Form 7 and Zoho CRM, Bigin <= 1.2.3 – Authenticated (Admin+) SQL Injection

The Integration for Contact Form 7 and Zoho CRM, Bigin plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in versions up to, and including, 1.2.3 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-1.2.3

Correctif

1.2.4

Publication

22/05/2023

CVE-2023-25976 Moyenne · 4,3
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin

Integration for Contact Form 7 and Zoho CRM, Bigin <= 1.2.2 – Cross-Site Request Forgery via settings_page function

The Integration for Contact Form 7 and Zoho CRM, Bigin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on the 'settings_page'…

Versions affectées

*-1.2.2

Correctif

1.2.3

Publication

22/02/2023

Vulnérabilité Moyenne · 6,1
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin

CRM Perks – Various Plugins (Various Versions) – Reflected Cross-Site Scripting

Multiple CRM Perks plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'vx_debug' parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…

Versions affectées

*-1.1.8

Correctif

1.1.9

Publication

26/08/2021

Vulnérabilité Moyenne · 6,1
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin

Integration for Contact Form 7 and Zoho CRM, Bigin <= 1.1.7 – Cross-Site Scripting

The Integration for Contact Form 7 and Zoho CRM, Bigin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘start_date’ and ‘end_date’ parameters in versions up to, and including, 1.1.7 due to insufficient input sanitization and…

Versions affectées

*-1.1.7

Correctif

1.1.8

Publication

25/08/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités