N/A
2026-02-13< 2.6.101
Smart Forms <= 2.6.100 - Missing Authorization to Authenticated (Subscriber+) Campaign Data Exposure
Minimum safe version
2.6.101
Update to 2.6.101 or later to address 11 fixable vulnerabilities
Smart Forms <= 2.6.100 - Missing Authorization to Authenticated (Subscriber+) Campaign Data Exposure
WordPress Smart Forms Plugin <= 2.6.98 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-1905
CVE-2024-33593
CVE-2024-1307
CVE-2024-1306
CVE-2023-7203
CVE-2023-49856
Smart Forms – when you need more than just a contact form <= 2.1.0 - Missing Authorization
WordPress Smart Forms plugin <= 2.5.15 - Cross-Site Request Forgery (CSRF) vulnerability
CVE-2022-0163