Extension WordPress
Vulnérabilités WS Form LITE – Drag & Drop Contact Form Builder
Cette page rassemble les failles publiées pour WS Form LITE – Drag & Drop Contact Form Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WS Form LITE – Drag & Drop Contact Form Builder
9 fiches
WS Form LITE – Drag & Drop Contact Form Builder for WordPress <= 1.10.35 – Missing Authorization to Unauthenticated Sensitive Information Exposure
The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_config' function in all versions up to,…
*-1.10.35
1.10.36
24/04/2025
WS Form LITE and PRO <= 1.10.13 – Unauthenticated Stored Cross-Site Scripting
The WS Form LITE and PRO plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the url parameter in all versions up to, and including, 1.10.13 due to insufficient input sanitization and output escaping. This makes it…
*-1.10.13
1.10.14
27/01/2025
WS Form LITE – Drag & Drop Contact Form Builder for WordPress <= 1.9.244 – Reflected Cross-Site Scripting via URL
The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up…
*-1.9.244
1.9.245
05/11/2024
WS Form LITE <= 1.9.238 – Unauthenticated Stored Cross-Site Scripting
The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.9.238 due to insufficient input sanitization and output escaping.…
*-1.9.238
1.9.244
25/09/2024
WS Form LITE <= 1.9.217 – Unauthenticated CSV Injection
The WS Form LITE plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.9.217. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when…
*-1.9.217
1.9.218
06/06/2024
WS Form LITE <= 1.9.170 – Authenticated(Administrator+) SQL Injection
The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 1.9.171 (exclusive) due to insufficient escaping on the…
[*, 1.9.171)
1.9.171
28/12/2023
WS Form LITE <= 1.9.117 – CAPTCHA Bypass
The WS Form LITE plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.9.117. This is due to the existence of a mechanism that allows the CAPTCHA to be bypassed if the client-side…
*-1.9.117
1.9.118
23/05/2023
WS Form LITE and WS Form Pro < 1.8.176 – Stored Cross-Site Scripting
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape submitted form data, allowing unauthenticated attacker to submit XSS payloads which will get executed when a privileged user will view the related submission
[*, 1.8.176)
1.8.176
31/01/2022
WS Form LITE and Pro < 1.8.176 – Stored Cross-Site Scripting
The WS Form LITE and Pro WordPress plugins before 1.8.176 do not sanitise and escape their Form Name, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
[*, 1.8.176)
1.8.176
31/01/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.