Missing Authorization
7 records63.6%First: 2014. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 11 vulnerability records associated with Smart Forms – when you need more than just a contact form, published between 2014 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
Use this history
A history record does not establish whether the version installed on your website is affected. Enter the exact version in the checker, or add this software to a private Critical/High alert watchlist.
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 1 | |
| 2019 | 1 | |
| 2022 | 1 | |
| 2023 | 1 | |
| 2024 | 5 | |
| 2025 | 1 | |
| 2026 | 1 |
| Severity | Records | Share |
|---|---|---|
| High | 3 | 27.3% |
| Medium | 7 | 63.6% |
| Informational | 1 | 9.1% |
First: 2014. Latest: 2026.
First: 2019. Latest: 2024.
First: 2024. Latest: 2025.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
2.6.1012.6.992.6.922.6.962.6.942.6.872.6.852.6.712.6.262.1.1Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-2.6.100 | Smart Forms <= 2.6.100 - Missing Authorization to Authenticated (Subscriber+) Campaign Data Exposure | February 13, 2026 | 2.6.101 | Medium |
*-2.6.98 | Smart Forms <= 2.6.98 - Authenticated (Admin+) Stored Cross-Site Scripting | May 23, 2025 | 2.6.99 | Medium |
*-2.6.91 | Smart Forms <= 2.6.91 - Missing Authorization to Notice Dismissal | April 25, 2024 | 2.6.92 | Medium |
*-2.6.93 | Smart Forms <= 2.6.93 - Cross-Site Request Forgery | April 15, 2024 | 2.6.94 | Medium |
*-2.6.95 | Smart Forms – when you need more than just a contact form <= 2.9.95 - Authenticated (Admin+) Stored Cross-Site Scripting | April 8, 2024 | 2.6.96 | Medium |
*-2.6.93 | Smart Forms <= 2.6.93 - Missing Authorization | March 25, 2024 | 2.6.94 | Medium |
*-2.6.86 | Smart Forms <= 2.6.86 - Missing Authorization | February 2, 2024 | 2.6.87 | Medium |
*-2.6.84 | Smart Forms <= 2.6.84 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update | December 7, 2023 | 2.6.85 | High |
[*, 2.6.71) | Smart Forms < 2.6.71 - Missing Authorization to Sensitive Information Disclosure | February 14, 2022 | 2.6.71 | Medium |
[*, 2.6.26) | Smart Forms < 2.6.26 - Cross-Site Request Forgery | February 28, 2019 | 2.6.26 | High |
*-2.1.0 | Smart Forms – when you need more than just a contact form <= 2.1.0 - Missing Authorization | November 6, 2014 | 2.1.1 | High |
Selected source records
Published: February 13, 2026
Published: May 23, 2025
Published: April 25, 2024
Published: April 15, 2024
Published: April 8, 2024
Published: March 25, 2024
Published: February 2, 2024
Published: December 7, 2023
Published: December 7, 2023
Published: February 28, 2019
Published: November 6, 2014
Published: February 14, 2022
Published: April 8, 2024
Published: May 23, 2025
Published: February 2, 2024
Published: February 13, 2026
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.