Extension WordPress

Vulnérabilités Smart Forms – when you need more than just a contact form

Cette page rassemble les failles publiées pour Smart Forms – when you need more than just a contact form, leurs plages de versions affectées et les correctifs signalés dans la base locale.

11Vulnérabilités
0Critiques
11Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Smart Forms – when you need more than just a contact form

11 fiches

CVE-2026-2022 Moyenne · 4,3
Smart Forms – when you need more than just a contact form

Smart Forms <= 2.6.100 – Missing Authorization to Authenticated (Subscriber+) Campaign Data Exposure

The Smart Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'rednao_smart_forms_get_campaigns' AJAX action in all versions up to, and including, 2.6.100. This makes it possible for authenticated…

Versions affectées

*-2.6.100

Correctif

2.6.101

Publication

13/02/2026

CVE-2024-33593 Informationnelle
Smart Forms – when you need more than just a contact form

Smart Forms <= 2.6.91 – Missing Authorization to Notice Dismissal

The Smart Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rednao_smart_forms_dont_show_again() function in versions up to, and including, 2.6.91. This makes it possible for authenticated attackers, with…

Versions affectées

*-2.6.91

Correctif

2.6.92

Publication

25/04/2024

CVE-2024-1905 Moyenne · 4,4
Smart Forms – when you need more than just a contact form

Smart Forms – when you need more than just a contact form <= 2.9.95 – Authenticated (Admin+) Stored Cross-Site Scripting

The Smart Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.6.95 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

*-2.6.95

Correctif

2.6.96

Publication

08/04/2024

CVE-2023-49856 Élevée · 8,8
Smart Forms – when you need more than just a contact form

Smart Forms <= 2.6.84 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

The Smart Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the smart_forms_save_settings() function hooked via AJAX in versions up to, and including, 2.6.84. This makes it possible for…

Versions affectées

*-2.6.84

Correctif

2.6.85

Publication

07/12/2023

CVE-2022-0163 Moyenne · 6,5
Smart Forms – when you need more than just a contact form

Smart Forms < 2.6.71 – Missing Authorization to Sensitive Information Disclosure

The Smart Forms WordPress plugin before 2.6.71 does not have authorisation in its rednao_smart_forms_entries_list AJAX action, allowing any authenticated users, such as subscriber, to download arbitrary form's data, which could include sensitive information such as PII depending on…

Versions affectées

[*, 2.6.71)

Correctif

2.6.71

Publication

14/02/2022

CVE-2014-8803 Élevée · 7,2
Smart Forms – when you need more than just a contact form

Smart Forms – when you need more than just a contact form <= 2.1.0 – Missing Authorization

The Smart Forms – when you need more than just a contact form plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the rednao_smart_forms_save_form_values function in versions up to, and including, 2.1.0.…

Versions affectées

*-2.1.0

Correctif

2.1.1

Publication

06/11/2014

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités