Known Vulnerabilities for Contact Form by Wpforms
Listed below are 3 of the newest known vulnerabilities associated with "Contact Form" by "Wpforms".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-105322 json | The Magee Shortcodes WordPress plugin through 2.1.1 does not restrict the recipient of some of its unauthenticated contact-fo... | Not Provided | 2026-10-07 | 2026-10-07 |
| CVE-2026-103909 json | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-101928 json | The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' para... | Not Provided | 2026-10-03 | 2026-10-03 |
| CVE-2026-100513 json | Contributor Cross Site Scripting (XSS) in CF7 Views – Complete Entry Management for Contact Form 7 <= 3.2.5 versions. | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-100184 json | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is... | Not Provided | 2026-10-01 | 2026-10-03 |
| CVE-2026-100179 json | The Calculated Fields Form – AI Form Builder for WordPress – Contact, Payment, Quote, Quiz & More plugin for WordPress is... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-97661 json | The Business Essentials for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'gateway' Fo... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-96833 json | Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions. | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-96813 json | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cro... | Not Provided | 2026-10-01 | 2026-10-03 |
| CVE-2026-96752 json | The Zero Spam for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Nested POST Array Keys via ... | Not Provided | 2026-09-25 | 2026-09-25 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wpforms | Contact Form | 1.5.9 |