WPForms records
16 published records for vendor wpforms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-862 Missing Authorization3
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-269 Improper Privilege Management1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-3574No exploit | WPForms Pro < 1.7.7 - CSV Injectionwpforms · wpforms pro · CWE-1236 | Critical9.8 | — | 1.4% | Nov 14, 2022 |
35Monitor | CVE-2024-56276No exploit | WordPress WPForms Lite plugin <= 1.9.2.2 - Broken Access Control vulnerabilitywpforms · wpforms · CWE-862 | High8.8 | — | 0.4% | Jan 7, 2025 |
32Monitor | CVE-2023-52209No exploit | WordPress WPForms User Registration plugin <= 2.1.0 - Authenticated Privilege Escalation vulnerabilitywpforms, llc. · wpforms user registration · CWE-269 | High8.0 | — | 0.4% | Aug 1, 2024 |
26Monitor | CVE-2024-11205No exploit | WPForms 1.8.4 - 1.9.2.1 - Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellationwpforms · wpforms · CWE-862 | Medium6.5 | — | 0.7% | Dec 10, 2024 |
24Monitor | CVE-2019-25145No exploit | Contact Form & SMTP Plugin by PirateForms <= 2.5.1 - Unauthenticated HTML injectionwpforms · contact form · CWE-79 | Medium6.1 | — | 0.7% | Jun 6, 2023 |
24Monitor | CVE-2023-7063No exploit | The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and wpforms · wpforms · CWE-79 | Medium6.1 | — | 0.5% | Jan 20, 2024 |
24Monitor | CVE-2023-30500No exploit | WordPress WPForms plugins - Reflected Cross Site Scripting (XSS) vulnerabilitywpforms · contact form · CWE-79 | Medium6.1 | — | 0.4% | Jun 22, 2023 |
24Monitor | CVE-2024-11272No exploit | Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSSwpforms · pirate forms · CWE-79 | Medium6.1 | — | 0.3% | Mar 25, 2025 |
24Monitor | CVE-2024-11273No exploit | Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSSwpforms · contact form · CWE-79 | Medium6.1 | — | 0.3% | Mar 25, 2025 |
22Monitor | CVE-2020-10385Proof of concept | A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.wpforms · contact form · CWE-79 | Medium5.4 | — | 4.4% | Mar 24, 2020 |
21Monitor | CVE-2023-3213No exploit | WP Mail SMTP Pro <= 3.8.0 - Missing Authorization to Information Dislcosure via is_print_pagewpforms · wp mail smtp · CWE-862 | Medium5.3 | — | 0.4% | Oct 3, 2023 |
21Monitor | CVE-2024-13403No exploit | WPForms Lite <= 1.9.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameterwpforms · wpforms · CWE-79 | Medium5.4 | — | 0.4% | Feb 4, 2025 |
20Monitor | CVE-2020-36919No exploit | WPForms 1.7.8 - Cross-Site Scripting (XSS)wpforms · wpforms · CWE-79 | Medium5.1 | — | 0.4% | Jan 13, 2026 |
18Monitor | CVE-2024-11223No exploit | WPForms < 1.9.2.3 - Admin+ Stored XSSwpforms · wpforms · CWE-79 | Medium4.7 | — | 0.5% | Dec 26, 2024 |
17Monitor | CVE-2024-10593No exploit | WPForms – Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletionwpforms · wpforms · CWE-352 | Medium4.3 | — | 0.3% | Nov 12, 2024 |
14Monitor | CVE-2024-7056No exploit | WPForms < 1.9.1.6 - Admin+ Stored XSSwpforms · wpforms · CWE-79 | Low3.5 | — | 0.5% | Nov 25, 2024 |
- CVE-2022-357439Monitor
WPForms Pro < 1.7.7 - CSV Injection
CriticalCVSS 9.8No exploitEPSS 1%wpforms · wpforms proNov 14, 2022
- CVE-2024-5627635Monitor
WordPress WPForms Lite plugin <= 1.9.2.2 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%wpforms · wpformsJan 7, 2025
- CVE-2023-5220932Monitor
WordPress WPForms User Registration plugin <= 2.1.0 - Authenticated Privilege Escalation vulnerability
HighCVSS 8.0No exploitEPSS 0%wpforms, llc. · wpforms user registrationAug 1, 2024
- CVE-2024-1120526Monitor
WPForms 1.8.4 - 1.9.2.1 - Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation
MediumCVSS 6.5No exploitEPSS 1%wpforms · wpformsDec 10, 2024
- CVE-2019-2514524Monitor
Contact Form & SMTP Plugin by PirateForms <= 2.5.1 - Unauthenticated HTML injection
MediumCVSS 6.1No exploitEPSS 1%wpforms · contact formJun 6, 2023
- CVE-2023-706324Monitor
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and
MediumCVSS 6.1No exploitEPSS 1%wpforms · wpformsJan 20, 2024
- CVE-2023-3050024Monitor
WordPress WPForms plugins - Reflected Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.1No exploitEPSS 0%wpforms · contact formJun 22, 2023
- CVE-2024-1127224Monitor
Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSS
MediumCVSS 6.1No exploitEPSS 0%wpforms · pirate formsMar 25, 2025
- CVE-2024-1127324Monitor
Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSS
MediumCVSS 6.1No exploitEPSS 0%wpforms · contact formMar 25, 2025
- CVE-2020-1038522Monitor
A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.
MediumCVSS 5.4Proof of conceptEPSS 4%wpforms · contact formMar 24, 2020
- CVE-2023-321321Monitor
WP Mail SMTP Pro <= 3.8.0 - Missing Authorization to Information Dislcosure via is_print_page
MediumCVSS 5.3No exploitEPSS 0%wpforms · wp mail smtpOct 3, 2023
- CVE-2024-1340321Monitor
WPForms Lite <= 1.9.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameter
MediumCVSS 5.4No exploitEPSS 0%wpforms · wpformsFeb 4, 2025
- CVE-2020-3691920Monitor
WPForms 1.7.8 - Cross-Site Scripting (XSS)
MediumCVSS 5.1No exploitEPSS 0%wpforms · wpformsJan 13, 2026
- CVE-2024-1122318Monitor
WPForms < 1.9.2.3 - Admin+ Stored XSS
MediumCVSS 4.7No exploitEPSS 1%wpforms · wpformsDec 26, 2024
- CVE-2024-1059317Monitor
WPForms – Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion
MediumCVSS 4.3No exploitEPSS 0%wpforms · wpformsNov 12, 2024
- CVE-2024-705614Monitor
WPForms < 1.9.1.6 - Admin+ Stored XSS
LowCVSS 3.5No exploitEPSS 0%wpforms · wpformsNov 25, 2024