Wpforms – easy form builder for wordpress – contact forms, payment forms, surveys, & more
This hub aggregates every CVE we track for Wpforms – easy form builder for wordpress – contact forms, payment forms, surveys, & more, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
6
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM5HIGH1
Monthly trend
0
0
1
1
0
1
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
2024-092026-08
Latest CVEs
The 6 most recently published vulnerabilities affecting Wpforms – easy form builder for wordpress – contact forms, payment forms, surveys, & more.
- CVE-2026-7792WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint5.3
- CVE-2025-3794WPForms Lite <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'start_timestamp' Parameter5.4
- CVE-2024-13403WPForms Lite <= 1.9.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameter6.4
- CVE-2024-11205WPForms 1.8.4 - 1.9.2.1 - Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation8.5
- CVE-2024-10593WPForms – Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion4.3
- CVE-2024-3649Contact Form by WPForms – Drag & Drop Form Builder for WordPress <= 1.8.7.2 - Unauthenticated Price Manipulation5.3
Product normalization is registry-driven with AI assist and human review. How it works