Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2024-56276
Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Missing Authorization vulnerability in WPForms Contact Form by WPForms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through 1.9.2.2.
0
Attacker Value
Unknown
CVE-2023-52209
Disclosure Date: August 01, 2024 (last updated August 02, 2024)
Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows Privilege Escalation.This issue affects WPForms User Registration: from n/a through 2.1.0.
0
Attacker Value
Unknown
CVE-2023-7063
Disclosure Date: January 20, 2024 (last updated January 31, 2024)
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including, 1.8.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-3213
Disclosure Date: October 04, 2023 (last updated November 09, 2023)
The WP Mail SMTP Pro plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the is_print_page function in versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to disclose potentially sensitive email information.
0
Attacker Value
Unknown
CVE-2023-30500
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 versions.
0
Attacker Value
Unknown
CVE-2019-25145
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The Contact Form & SMTP Plugin by PirateForms plugin for WordPress is vulnerable to HTML injection in the ‘public/class-pirateforms-public.php’ file in versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary HTML in emails that could be used to phish unsuspecting victims.
0
Attacker Value
Unknown
CVE-2022-3574
Disclosure Date: November 14, 2022 (last updated December 22, 2024)
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.
0
Attacker Value
Unknown
CVE-2020-10385
Disclosure Date: March 24, 2020 (last updated November 27, 2024)
A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.
0