Weformspro maintains a narrowly focused web form and data-collection product suite that, despite limited prevalence, has surfaced vulnerabilities skewing toward critical severity. The recurring weakness classes center on input-handling and authorization issues—cross-site scripting, missing authorization controls, and formula-injection in exported data—characteristic of form-processing applications that handle untrusted user input and manage access boundaries. Defenders should treat updates to this vendor's products as high-priority given the severity profile; live exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Weformspro over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-22276CRITICAL WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry. | Nov 4, 2020 | 9.8 | 31 | NO | NO |
CVE-2024-30512CRITICAL Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.20. | Jun 9, 2024 | 9.1 | 24 | NO | NO |
CVE-2023-51524HIGH Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.18. | Jun 12, 2024 | 8.8 | 23 | NO | NO |
CVE-2022-2395MEDIUM The weForms WordPress plugin before 1.6.14 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when | Aug 8, 2022 | 4.8 | 20 | NO | NO |
CVE-2024-0386MEDIUM The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versions up to, and including, 1.6.21 due to insufficient input s | Mar 12, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-50896MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weForms weForms – Easy Drag & Drop Contact Form Builder For WordPress allows S | Dec 29, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Weformspro.
Media articles that mention a CVE ID that affects a product developed by Weformspro — matched by CVE ID, not by vendor name.