weformspro records
7 published records for vendor weformspro.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 57.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-862 Missing Authorization2
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-602 Client-Side Enforcement of Server-Side Security1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-22276No exploit | WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.weformspro · weforms · CWE-1236 | Critical9.8 | — | 3.0% | Nov 4, 2020 |
36Monitor | CVE-2024-30512No exploit | WordPress weForms plugin <= 1.6.20 - Broken Access Control vulnerabilityweformspro · weforms · CWE-862 | Critical9.1 | — | 0.4% | Jun 9, 2024 |
35Monitor | CVE-2023-51524No exploit | WordPress weForms plugin <= 1.6.18 - Broken Access Control vulnerabilityweformspro · weforms · CWE-862 | High8.8 | — | 0.3% | Jun 12, 2024 |
24Monitor | CVE-2024-0386No exploit | weForms <= 1.6.21 - Unauthenticated Stored Cross-Site Scripting via Refererweformspro · weforms · CWE-79 | Medium6.1 | — | 0.6% | Mar 12, 2024 |
21Monitor | CVE-2024-32512No exploit | WordPress weForms plugin <= 1.6.20 - Form Submission Restriction Bypass vulnerabilityweforms · weforms · CWE-602 | Medium5.3 | — | 0.3% | May 17, 2024 |
19Monitor | CVE-2022-2395No exploit | weForms < 1.6.14 - Admin+ Stored Cross-Site Scriptingweformspro · weforms · CWE-79 | Medium4.8 | — | 0.6% | Aug 8, 2022 |
19Monitor | CVE-2023-50896No exploit | WordPress weForms Plugin <= 1.6.17 is vulnerable to Cross Site Scripting (XSS)weformspro · weforms · CWE-79 | Medium4.8 | — | 0.3% | Dec 29, 2023 |
- CVE-2020-2227640Plan
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
CriticalCVSS 9.8No exploitEPSS 3%weformspro · weformsNov 4, 2020
- CVE-2024-3051236Monitor
WordPress weForms plugin <= 1.6.20 - Broken Access Control vulnerability
CriticalCVSS 9.1No exploitEPSS 0%weformspro · weformsJun 9, 2024
- CVE-2023-5152435Monitor
WordPress weForms plugin <= 1.6.18 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%weformspro · weformsJun 12, 2024
- CVE-2024-038624Monitor
weForms <= 1.6.21 - Unauthenticated Stored Cross-Site Scripting via Referer
MediumCVSS 6.1No exploitEPSS 1%weformspro · weformsMar 12, 2024
- CVE-2024-3251221Monitor
WordPress weForms plugin <= 1.6.20 - Form Submission Restriction Bypass vulnerability
MediumCVSS 5.3No exploitEPSS 0%weforms · weformsMay 17, 2024
- CVE-2022-239519Monitor
weForms < 1.6.14 - Admin+ Stored Cross-Site Scripting
MediumCVSS 4.8No exploitEPSS 1%weformspro · weformsAug 8, 2022
- CVE-2023-5089619Monitor
WordPress weForms Plugin <= 1.6.17 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 4.8No exploitEPSS 0%weformspro · weformsDec 29, 2023