Extension WordPress

Vulnérabilités Lead Form Builder & Contact Form

Cette page rassemble les failles publiées pour Lead Form Builder & Contact Form, leurs plages de versions affectées et les correctifs signalés dans la base locale.

12Vulnérabilités
0Critiques
12Avec correctif
7,2CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Lead Form Builder & Contact Form

12 fiches

CVE-2026-32532 Élevée · 7,2
Lead Form Builder & Contact Form

Lead Form Builder & Contact Form <= 2.0.1 – Unauthenticated Stored Cross-Site Scripting

The Lead Form Builder & Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

Versions affectées

*-2.0.1

Correctif

2.0.2

Publication

23/03/2026

CVE-2026-1454 Élevée · 7,2
Lead Form Builder & Contact Form

Responsive Contact Form Builder & Lead Generation Plugin <= 2.0.1 – Unauthenticated Stored Cross-Site Scripting

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.0.1 via form field submissions. This is due to insufficient input sanitization in…

Versions affectées

*-2.0.1

Correctif

2.0.2

Publication

10/03/2026

CVE-2025-68046 Moyenne · 4,3
Lead Form Builder & Contact Form

Contact Form & Lead Form Elementor Builder <= 2.0.1 – Authenticated (Subscriber+) Information Exposure

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above,…

Versions affectées

*-2.0.1

Correctif

2.0.2

Publication

20/01/2026

CVE-2024-10475 Moyenne · 4,4
Lead Form Builder & Contact Form

Responsive Contact Form Builder & Lead Generation Plugin <= 1.9.7 – Authenticated (Admin+) Stored Cross-Site Scripting

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-1.9.7

Correctif

1.9.8

Publication

03/03/2025

CVE-2024-4261 Moyenne · 5,4
Lead Form Builder & Contact Form

Responsive Contact Form Builder & Lead Generation Plugin <= 1.9.1 – Authenticated (Subscriber+) Arbitrary Shortcode Execution

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.1. This is due to the software allowing users to execute an action…

Versions affectées

*-1.9.1

Correctif

1.9.2

Publication

21/05/2024

CVE-2024-3637 Moyenne · 6,6
Lead Form Builder & Contact Form

Responsive Contact Form Builder & Lead Generation Plugin <= 1.9.7 – Authenticated (Admin+) Stored Cross-Site Scripting

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping. This…

Versions affectées

*-1.9.7

Correctif

1.9.8

Publication

12/04/2024

CVE-2024-1415 Moyenne · 4,3
Lead Form Builder & Contact Form

Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 – Cross-Site Request Forgery

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.9. This is due to missing or incorrect nonce validation on several functions.…

Versions affectées

*-1.8.9

Correctif

1.9.0

Publication

11/04/2024

CVE-2023-25969 Moyenne · 6,5
Lead Form Builder & Contact Form

Multiple Plugins By ThemeHunk (Various Versions) – Missing Authorization via settings_init

Multiple Plugins By ThemeHunk are vulnerable to unauthorized plugin setting modification due to a missing capability check on the settings_init function in various versions. This makes it possible for unauthenticated attackers to reset plugin settings.

Versions affectées

*-1.8.4

Correctif

1.8.5

Publication

22/03/2023

CVE-2022-23179 Moyenne · 4,4
Lead Form Builder & Contact Form

Responsive Contact Form Builder & Lead Generation Plugin < 1.7.0 – Authenticated (Admin+) Stored Cross-Site Scripting

The Responsive Contact Form Builder & Lead Generation Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to 1.7.0 (exclusive) due to insufficient input sanitization and output escaping. This makes…

Versions affectées

[*, 1.7.0)

Correctif

1.7.0

Publication

05/01/2022

CVE-2021-24967 Élevée · 7,2
Lead Form Builder & Contact Form

Contact Form & Lead Form Elementor Builder <= 1.6.3 – Unauthenticated Stored Cross-Site Scripting

The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted Leads

Versions affectées

*-1.6.3

Correctif

1.6.4

Publication

29/11/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités