Input validation vulnerability in Contact Form by WPForms – Drag & Drop Form Builder for WordPress 1.8.1.2

The Contact Form by WPForms (Free and Premium) plugin for WordPress has a security vulnerability in versions that are up to and including 1.8.1.2. This vulnerability can allow someone without access to the website to inject malicious web scripts into pages that execute when a user clicks on a link or performs some other action. This is due to the plugin not properly filtering and escaping data when displaying debug information.

Detected in:

Contact Form by WPForms – Drag & Drop Form Builder for WordPress fixed vulnerable versions: >= * <= 1.8.1.2
WPForms Pro fixed vulnerable versions: >= * <= 1.8.1.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.