Extension WordPress

Vulnérabilités WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

Cette page rassemble les failles publiées pour WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More, leurs plages de versions affectées et les correctifs signalés dans la base locale.

21Vulnérabilités
0Critiques
21Avec correctif
8,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

21 fiches

CVE-2026-15782 Moyenne · 4,9
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

WPForms <= 2.0.0.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content

The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content in all versions…

Versions affectées

*-2.0.0.1

Correctif

2.0.0.2

Publication

20/07/2026

CVE-2026-12127 Moyenne · 5,3
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

WPForms <= 1.10.2 – Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in all versions up to, and including, 1.10.2 This…

Versions affectées

*-1.10.2

Correctif

1.10.2.1

Publication

30/06/2026

CVE-2026-7792 Moyenne · 5,3
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

WPForms <= 1.10.0.4 – Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to and including 1.10.0.1. This is due to…

Versions affectées

*-1.10.0.4

Correctif

1.10.0.5

Publication

05/06/2026

CVE-2026-48835 Moyenne · 5,3
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More <= 1.10.0.4 – Missing Authorization

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and…

Versions affectées

*-1.10.0.4

Correctif

1.10.0.5

Publication

28/05/2026

CVE-2026-40764 Moyenne · 4,3
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

Contact Form by WPForms <= 1.10.0.2 – Cross-Site Request Forgery

The Contact Form by WPForms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.0.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for…

Versions affectées

*-1.10.0.2

Correctif

1.10.0.3

Publication

31/03/2026

CVE-2026-25339 Moyenne · 5,3
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More <= 1.9.8.7 – Unauthenticated Sensitive Information Exposure

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.8.7. This makes it possible for…

Versions affectées

*-1.9.8.7

Correctif

1.9.9.2

Publication

23/03/2026

CVE-2026-32446 Moyenne · 4,3
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

Contact Form by WPForms <= 1.9.9.3 – Missing Authorization

The Contact Form by WPForms plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.9.9.3. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-1.9.9.3

Correctif

1.9.9.4

Publication

07/03/2026

CVE-2025-3794 Moyenne · 5,4
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

WPForms Lite <= 1.9.5 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'start_timestamp' Parameter

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the start_timestamp parameter in all versions up to, and including, 1.9.5 due…

Versions affectées

*-1.9.5

Correctif

1.9.5.1

Publication

09/05/2025

CVE-2024-13403 Moyenne · 6,4
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

WPForms Lite <= 1.9.3.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameter

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fieldHTML’ parameter in all versions up to, and including, 1.9.3.1 due…

Versions affectées

*-1.9.3.1

Correctif

1.9.3.2

Publication

03/02/2025

CVE-2024-56276 Moyenne · 4,3
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

Contact Form by WPForms <= 1.9.2.2 – Missing Authorization

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to,…

Versions affectées

*-1.9.2.2

Correctif

1.9.2.3

Publication

03/01/2025

CVE-2024-11205 Élevée · 8,5
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

WPForms 1.8.4 – 1.9.2.1 – Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation

The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting from 1.8.4 up to, and including, 1.9.2.1. This makes it possible for authenticated…

Versions affectées

1.8.4-1.9.2.1

Correctif

1.9.2.2

Publication

09/12/2024

CVE-2024-11223 Moyenne · 4,4
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

WPForms <= 1.9.2.2 – Authenticated (Admin+) Stored Cross-Site Scripting

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.2.2 due to…

Versions affectées

*-1.9.2.2

Correctif

1.9.2.3

Publication

05/12/2024

CVE-2024-10593 Moyenne · 4,3
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

WPForms – Easy Form Builder for WordPress <= 1.9.1.6 – Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.1.6. This is due to missing…

Versions affectées

*-1.9.1.6

Correctif

1.9.2.1

Publication

12/11/2024

CVE-2024-7056 Moyenne · 4,4
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

WPForms <= 1.9.1.5 – Authenticated (Administrator+) Stored Cross-Site Scripting

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.9.1.5 due to…

Versions affectées

*-1.9.1.5

Correctif

1.9.1.6

Publication

04/11/2024

CVE-2024-3649 Moyenne · 5,3
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

Contact Form by WPForms – Drag & Drop Form Builder for WordPress <= 1.8.7.2 – Unauthenticated Price Manipulation

The Contact Form by WPForms – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to price manipulation in versions up to, and including, 1.8.7.2. This is due to a lack of controls on several…

Versions affectées

*-1.8.7.2

Correctif

1.8.8.2

Publication

01/05/2024

CVE-2023-30500 Moyenne · 6,1
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

Contact Form by WPForms (Free and Premium) <= 1.8.1.2 – Reflected Cross-Site Scripting

The Contact Form by WPForms (Free and Premium) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.8.1.2 due to insufficient input sanitization and output escaping on debug data. This makes it…

Versions affectées

*-1.8.1.2

Correctif

1.8.1.3

Publication

20/06/2023

Vulnérabilité Moyenne · 6,8
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

Contact Form by WPForms <= 1.7.5.3 – Authenticated (Administrator+) Arbitrary File Access via Path Traversal

The Contact Form by WPForms plugin for WordPress is vulnerable to Directory Traversal via email template paths in versions up to, and including, 1.7.5.3. This allows administrator-level attackers to read the contents of arbitrary files on the server,…

Versions affectées

*-1.7.5.3

Correctif

1.7.5.5

Publication

19/09/2022

Vulnérabilité Élevée · 7,2
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

Contact Form by WPForms <= 1.6.0.1 – Cross-Site Scripting

The Contact Form by WPForms plugin for WordPress has a Cross-Site Scripting vulnerability, which is caused by improper input sanitization of user input via the choice label parameter in versions up to, and including, 1.6.0.1.

Versions affectées

[*, 1.6.0.2)

Correctif

1.6.0.2

Publication

21/05/2020

Vulnérabilité Élevée · 7,1
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More

Contact Form by WPForms <= 1.4.8 – Reflected Cross-Site Scripting

The Contact Form by WPForms for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…

Versions affectées

[*, 1.4.8.1)

Correctif

1.4.8.1

Publication

10/12/2018

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités