WPForms kayıtları
wpforms üreticisine ait 16 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-862 Missing Authorization3
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-269 Improper Privilege Management1
- CWE-352 Cross-Site Request Forgery (CSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
16 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2022-3574İstismar yok | WPForms Pro < 1.7.7 - CSV Injectionwpforms · wpforms pro · CWE-1236 | Kritik9,8 | — | %1,4 | 14 Kas 2022 |
35İzleyin | CVE-2024-56276İstismar yok | WordPress WPForms Lite plugin <= 1.9.2.2 - Broken Access Control vulnerabilitywpforms · wpforms · CWE-862 | Yüksek8,8 | — | %0,4 | 7 Oca 2025 |
32İzleyin | CVE-2023-52209İstismar yok | WordPress WPForms User Registration plugin <= 2.1.0 - Authenticated Privilege Escalation vulnerabilitywpforms, llc. · wpforms user registration · CWE-269 | Yüksek8,0 | — | %0,4 | 1 Ağu 2024 |
26İzleyin | CVE-2024-11205İstismar yok | WPForms 1.8.4 - 1.9.2.1 - Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellationwpforms · wpforms · CWE-862 | Orta6,5 | — | %0,7 | 10 Ara 2024 |
24İzleyin | CVE-2019-25145İstismar yok | Contact Form & SMTP Plugin by PirateForms <= 2.5.1 - Unauthenticated HTML injectionwpforms · contact form · CWE-79 | Orta6,1 | — | %0,7 | 6 Haz 2023 |
24İzleyin | CVE-2023-7063İstismar yok | The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and wpforms · wpforms · CWE-79 | Orta6,1 | — | %0,5 | 20 Oca 2024 |
24İzleyin | CVE-2023-30500İstismar yok | WordPress WPForms plugins - Reflected Cross Site Scripting (XSS) vulnerabilitywpforms · contact form · CWE-79 | Orta6,1 | — | %0,4 | 22 Haz 2023 |
24İzleyin | CVE-2024-11272İstismar yok | Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSSwpforms · pirate forms · CWE-79 | Orta6,1 | — | %0,3 | 25 Mar 2025 |
24İzleyin | CVE-2024-11273İstismar yok | Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSSwpforms · contact form · CWE-79 | Orta6,1 | — | %0,3 | 25 Mar 2025 |
22İzleyin | CVE-2020-10385Kavram kanıtı | A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.wpforms · contact form · CWE-79 | Orta5,4 | — | %4,4 | 24 Mar 2020 |
21İzleyin | CVE-2023-3213İstismar yok | WP Mail SMTP Pro <= 3.8.0 - Missing Authorization to Information Dislcosure via is_print_pagewpforms · wp mail smtp · CWE-862 | Orta5,3 | — | %0,4 | 3 Eki 2023 |
21İzleyin | CVE-2024-13403İstismar yok | WPForms Lite <= 1.9.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameterwpforms · wpforms · CWE-79 | Orta5,4 | — | %0,4 | 4 Şub 2025 |
20İzleyin | CVE-2020-36919İstismar yok | WPForms 1.7.8 - Cross-Site Scripting (XSS)wpforms · wpforms · CWE-79 | Orta5,1 | — | %0,4 | 13 Oca 2026 |
18İzleyin | CVE-2024-11223İstismar yok | WPForms < 1.9.2.3 - Admin+ Stored XSSwpforms · wpforms · CWE-79 | Orta4,7 | — | %0,5 | 26 Ara 2024 |
17İzleyin | CVE-2024-10593İstismar yok | WPForms – Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletionwpforms · wpforms · CWE-352 | Orta4,3 | — | %0,3 | 12 Kas 2024 |
14İzleyin | CVE-2024-7056İstismar yok | WPForms < 1.9.1.6 - Admin+ Stored XSSwpforms · wpforms · CWE-79 | Düşük3,5 | — | %0,5 | 25 Kas 2024 |
- CVE-2022-357439İzleyin
WPForms Pro < 1.7.7 - CSV Injection
KritikCVSS 9,8İstismar yokEPSS %1wpforms · wpforms pro14 Kas 2022
- CVE-2024-5627635İzleyin
WordPress WPForms Lite plugin <= 1.9.2.2 - Broken Access Control vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0wpforms · wpforms7 Oca 2025
- CVE-2023-5220932İzleyin
WordPress WPForms User Registration plugin <= 2.1.0 - Authenticated Privilege Escalation vulnerability
YüksekCVSS 8,0İstismar yokEPSS %0wpforms, llc. · wpforms user registration1 Ağu 2024
- CVE-2024-1120526İzleyin
WPForms 1.8.4 - 1.9.2.1 - Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation
OrtaCVSS 6,5İstismar yokEPSS %1wpforms · wpforms10 Ara 2024
- CVE-2019-2514524İzleyin
Contact Form & SMTP Plugin by PirateForms <= 2.5.1 - Unauthenticated HTML injection
OrtaCVSS 6,1İstismar yokEPSS %1wpforms · contact form6 Haz 2023
- CVE-2023-706324İzleyin
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and
OrtaCVSS 6,1İstismar yokEPSS %1wpforms · wpforms20 Oca 2024
- CVE-2023-3050024İzleyin
WordPress WPForms plugins - Reflected Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,1İstismar yokEPSS %0wpforms · contact form22 Haz 2023
- CVE-2024-1127224İzleyin
Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSS
OrtaCVSS 6,1İstismar yokEPSS %0wpforms · pirate forms25 Mar 2025
- CVE-2024-1127324İzleyin
Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSS
OrtaCVSS 6,1İstismar yokEPSS %0wpforms · contact form25 Mar 2025
- CVE-2020-1038522İzleyin
A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.
OrtaCVSS 5,4Kavram kanıtıEPSS %4wpforms · contact form24 Mar 2020
- CVE-2023-321321İzleyin
WP Mail SMTP Pro <= 3.8.0 - Missing Authorization to Information Dislcosure via is_print_page
OrtaCVSS 5,3İstismar yokEPSS %0wpforms · wp mail smtp3 Eki 2023
- CVE-2024-1340321İzleyin
WPForms Lite <= 1.9.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameter
OrtaCVSS 5,4İstismar yokEPSS %0wpforms · wpforms4 Şub 2025
- CVE-2020-3691920İzleyin
WPForms 1.7.8 - Cross-Site Scripting (XSS)
OrtaCVSS 5,1İstismar yokEPSS %0wpforms · wpforms13 Oca 2026
- CVE-2024-1122318İzleyin
WPForms < 1.9.2.3 - Admin+ Stored XSS
OrtaCVSS 4,7İstismar yokEPSS %1wpforms · wpforms26 Ara 2024
- CVE-2024-1059317İzleyin
WPForms – Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion
OrtaCVSS 4,3İstismar yokEPSS %0wpforms · wpforms12 Kas 2024
- CVE-2024-705614İzleyin
WPForms < 1.9.1.6 - Admin+ Stored XSS
DüşükCVSS 3,5İstismar yokEPSS %0wpforms · wpforms25 Kas 2024