Input validation vulnerability in weForms – Easy Drag & Drop Contact Form Builder For WordPress 1.6.21

The weForms add-on for WordPress has a security vulnerability that allows attackers to insert harmful scripts into web pages. This can happen when a user accesses a page that has been injected with these scripts. The vulnerability exists in all versions up to and including 1.6.21, as the input is not properly sanitized and the output is not properly escaped. This means that even users who are not logged in can exploit this vulnerability.

Detected in:

weForms – Easy Drag & Drop Contact Form Builder For WordPress fixed vulnerable versions: >= * <= 1.6.21

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.