Weforms – easy drag & drop contact form builder for wordpress
This hub aggregates every CVE we track for Weforms – easy drag & drop contact form builder for wordpress, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
3
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM2HIGH1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
2024-092026-08
Latest CVEs
The 3 most recently published vulnerabilities affecting Weforms – easy drag & drop contact form builder for wordpress.
- CVE-2026-2707weForms <= 1.6.27 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Hidden Field Value via REST API6.4
- CVE-2024-0386weForms <= 1.6.21 - Unauthenticated Stored Cross-Site Scripting via Referer7.2
- CVE-2023-50896WordPress weForms Plugin <= 1.6.17 is vulnerable to Cross Site Scripting (XSS)5.9
Product normalization is registry-driven with AI assist and human review. How it works