Extension WordPress
Vulnérabilités Smart Forms – when you need more than just a contact form
Cette page rassemble les failles publiées pour Smart Forms – when you need more than just a contact form, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Smart Forms – when you need more than just a contact form
11 fiches
Smart Forms <= 2.6.100 – Missing Authorization to Authenticated (Subscriber+) Campaign Data Exposure
The Smart Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'rednao_smart_forms_get_campaigns' AJAX action in all versions up to, and including, 2.6.100. This makes it possible for authenticated…
*-2.6.100
2.6.101
13/02/2026
Smart Forms <= 2.6.98 – Authenticated (Admin+) Stored Cross-Site Scripting
The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6.98 due to insufficient input sanitization…
*-2.6.98
2.6.99
23/05/2025
Smart Forms <= 2.6.91 – Missing Authorization to Notice Dismissal
The Smart Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rednao_smart_forms_dont_show_again() function in versions up to, and including, 2.6.91. This makes it possible for authenticated attackers, with…
*-2.6.91
2.6.92
25/04/2024
Smart Forms <= 2.6.93 – Cross-Site Request Forgery
The Smart Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.93. This is due to missing or incorrect nonce validation on several functions in the smart-forms-ajax.php file. This makes…
*-2.6.93
2.6.94
15/04/2024
Smart Forms – when you need more than just a contact form <= 2.9.95 – Authenticated (Admin+) Stored Cross-Site Scripting
The Smart Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6.95 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
*-2.6.95
2.6.96
08/04/2024
Smart Forms <= 2.6.93 – Missing Authorization
The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in the smart-forms-ajax.php file in all…
*-2.6.93
2.6.94
25/03/2024
Smart Forms <= 2.6.86 – Missing Authorization
The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the rednao_smart_form_delete_entries() AJAX action in all versions up to, and…
*-2.6.86
2.6.87
02/02/2024
Smart Forms <= 2.6.84 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
The Smart Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the smart_forms_save_settings() function hooked via AJAX in versions up to, and including, 2.6.84. This makes it possible for…
*-2.6.84
2.6.85
07/12/2023
Smart Forms < 2.6.71 – Missing Authorization to Sensitive Information Disclosure
The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, which could include sensitive information such as PII depending on…
[*, 2.6.71)
2.6.71
14/02/2022
Smart Forms < 2.6.26 – Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.
[*, 2.6.26)
2.6.26
28/02/2019
Smart Forms – when you need more than just a contact form <= 2.1.0 – Missing Authorization
The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the rednao_smart_forms_save_form_values function in versions up to, and including, 2.1.0.…
*-2.1.0
2.1.1
06/11/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.