Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wpforms MEDIUM 6.1
CVE-2020-36919

WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attackers can inject malicious scr…

Fix: after 1.7.8
Fix from $1,600 2026-01-13
Pirate Forms MEDIUM 6.1
CVE-2024-11272

The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which co…

Fix: 2.6.0+
Fix from $1,600 2025-03-25
Contact Form MEDIUM 6.1
CVE-2024-11273

The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which co…

Fix: 2.6.0+
Fix from $1,600 2025-03-25
Wpforms MEDIUM 5.4
CVE-2024-13403

The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Stored Cross-Site…

Fix: 1.9.3.2+
Fix from $1,600 2025-02-04
Wpforms HIGH 8.8
CVE-2024-56276

Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Configured Access Control Secur…

Fix: 1.9.2.3+
Fix from $1,950 2025-01-07
Wpforms MEDIUM 6.5
CVE-2024-11205

The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' …

Fix: 1.9.2.2+
Fix from $1,600 2024-12-10
Wpforms MEDIUM 6.1
CVE-2023-7063

The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including…

Fix: after 1.8.5.3
Fix from $1,600 2024-01-20
Wp Mail Smtp MEDIUM 5.3
CVE-2023-3213

The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_print_page functio…

Fix: after 3.8.0
Fix from $1,600 2023-10-04
Contact Form MEDIUM 6.1
CVE-2023-30500

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 v…

Fix: after 1.8.1.2
Fix from $1,600 2023-06-22
Contact Form MEDIUM 6.1
CVE-2019-25145

The Contact Form & SMTP Plugin by PirateForms plugin for WordPress is vulnerable to HTML injection in the ‘public/class-pirateforms-public.php’ file …

Fix: after 2.5.1
Fix from $1,600 2023-06-07
Wpforms Pro CRITICAL 9.8
CVE-2022-3574

The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.

Fix: 1.7.7+
Fix from $2,300 2022-11-14
Contact Form MEDIUM 5.4
CVE-2020-10385

A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.

Fix: 1.5.9+
Fix from $1,600 2020-03-24