CVE-2026-40764
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
Minimum safe version
1.10.0.3
Update to 1.10.0.3 or later to address 24 fixable vulnerabilities
CVE-2026-25339
CVE-2026-32446
CVE-2020-36919
WPForms Lite <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'start_timestamp' Parameter
CVE-2024-13403
CVE-2024-56276
CVE-2024-11223
CVE-2024-11205
CVE-2024-7056
CVE-2024-10593
CVE-2024-3649
Contact Form by WPForms < 1.4.8 - Authenticated Stored Cross-Site Scripting (XSS)
Contact Form by WPForms < 1.4.8.1 - Unauthenticated Cross-Site Scripting (XSS)
Contact Form by WPForms < 1.6.0.2 - Authenticated Stored Cross-Site Scripting (XSS)
Contact Form by WPForms < 1.7.5.5 - Admin+ Arbitrary File Access
CVE-2023-30500
Contact Form by WPForms – Drag & Drop Form Builder for WordPress <= 1.4.7.2 - Stored Cross-Site Scripting
Contact Form by WPForms <= 1.4.8 - Reflected Cross-Site Scripting
Contact Form by WPForms <= 1.6.0.1 - Cross-Site Scripting
Contact Form by WPForms <= 1.7.5.3 - Authenticated (Administrator+) Arbitrary File Access via Path Traversal
WordPress Contact Form by WPForms plugin <= 1.7.5.3 - Authenticated Arbitrary File Access vulnerability
WordPress Contact Form by WPForms plugin <= 1.4.7 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
WordPress Contact Form by WPForms plugin <= 1.4.8 - Unauthenticated Cross-Site Scripting (XSS) vulnerability
WordPress Contact Form by WPForms plugin <= 1.6.0.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
CVE-2020-10385