Input validation vulnerability in WS Form LITE – Drag & Drop Contact Form Builder for WordPress 1.10.13

A plugin for WordPress called WS Form LITE has a security issue that can be exploited by hackers. This issue, known as Stored Cross-Site Scripting, allows attackers to insert harmful code into web pages, which will run whenever a user visits that page. This vulnerability affects all versions of the plugin up to version 1.10.13, but it has been partially fixed in version 1.10.13 and completely fixed in version 1.10.14.

Detected in:

WS Form LITE – Drag & Drop Contact Form Builder for WordPress fixed vulnerable versions: >= * <= 1.10.13
WS Form Pro fixed vulnerable versions: >= * <= 1.10.13

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.