Known Vulnerabilities for Wp Form Builder by Web-dorado

Listed below are 1 of the newest known vulnerabilities associated with "Wp Form Builder" by "Web-dorado".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-32532 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Contact Form ... Not Provided 2026-03-25 2026-03-25
CVE-2026-32498 Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager a... Not Provided 2026-03-25 2026-03-26
CVE-2026-24373 Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-... Not Provided 2026-03-25 2026-03-27
CVE-2026-4987 The SureForms – Contact Form, Payment Form & Other Custom Form Builder plugin for WordPress is vulnerable to Payment Amount... Not Provided 2026-03-28 2026-03-30
CVE-2026-2442 The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralization o... Not Provided 2026-03-28 2026-03-30
CVE-2026-1307 The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Sensitive Information Ex... Not Provided 2026-03-28 2026-03-30
CVE-2025-54678 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Easy For... Not Provided 2025-08-14 2026-04-01
CVE-2025-49399 Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Cross Site Reques... Not Provided 2025-08-20 2026-04-01
CVE-2025-48333 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPQuark eForm - WordPre... Not Provided 2025-06-17 2026-04-01
CVE-2025-47690 Missing Authorization vulnerability in Smackcoders Inc., Lead Form Data Collection to CRM wp-leads-builder-any-crm allows Pri... Not Provided 2025-05-23 2026-04-01

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationWeb-doradoWp Form Builder1.0.9AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.8AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.7AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.69AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.68AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.67AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.66AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.65AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.64AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.63AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.62AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.61AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.60AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.6AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.59AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.58AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.57AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.56AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.55AllAllAll
ApplicationWeb-doradoWp Form Builder1.0.54AllAllAll
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report