WPForms is a focused WordPress plugin ecosystem spanning form-building and email-delivery tools, with a modestly represented footprint in the vulnerability landscape. Its disclosures cluster around web-application input-handling and authorization weaknesses—cross-site scripting, CSRF, missing authorization checks, and CSV injection—typical of plugins that process user-submitted data and integrate with WordPress permission models; vulnerabilities across the portfolio lean toward moderate-to-serious severity and have a moderate tendency to acquire public proof-of-concept code. Defenders managing WordPress deployments should monitor this vendor's plugin releases and apply patches promptly to internet-facing forms; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpforms over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3574CRITICAL The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection. | Nov 14, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-10385MEDIUM A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress. | Mar 24, 2020 | 5.4 | 24 | NO | YES |
CVE-2024-56276HIGH Missing Authorization vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects C | Jan 7, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-11205MEDIUM The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting f | Dec 10, 2024 | 6.5 | 23 | NO | NO |
CVE-2020-36919MEDIUM WPForms 1.7.8 contains a cross-site scripting vulnerability in the slider import search feature and tab parameter. Attackers can inject malicious scripts through the ListTable.php | Jan 13, 2026 | 6.1 | 21 | NO | NO |
CVE-2023-7063MEDIUM The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including, 1.8.5.3 due to insufficient i | Jan 20, 2024 | 6.1 | 19 | NO | NO |
CVE-2023-30500MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPForms WPForms Lite (wpforms-lite), WPForms WPForms Pro (wpforms) plugins <= 1.8.1.2 versions. | Jun 22, 2023 | 6.1 | 19 | NO | NO |
CVE-2019-25145MEDIUM The Contact Form & SMTP Plugin by PirateForms plugin for WordPress is vulnerable to HTML injection in the ‘public/class-pirateforms-public.php’ file in versions up to, and includin | Jun 7, 2023 | 6.1 | 19 | NO | NO |
CVE-2024-11273MEDIUM The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users | Mar 25, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-11272MEDIUM The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape some of its settings, which could allow high privilege users | Mar 25, 2025 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpforms.
Media articles that mention a CVE ID that affects a product developed by Wpforms — matched by CVE ID, not by vendor name.