Cross-Site Scripting
10 records47.6%First: 2018. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 21 vulnerability records associated with WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More, published between 2018 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2018 | 2 | |
| 2020 | 2 | |
| 2022 | 1 | |
| 2023 | 1 | |
| 2024 | 5 | |
| 2025 | 3 | |
| 2026 | 7 |
| Severity | Records | Share |
|---|---|---|
| High | 3 | 14.3% |
| Medium | 18 | 85.7% |
First: 2018. Latest: 2026.
First: 2024. Latest: 2026.
First: 2024. Latest: 2026.
First: 2024. Latest: 2026.
First: 2022. Latest: 2022.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
2.0.0.21.10.2.11.10.0.51.10.0.31.9.9.21.9.9.41.9.5.11.9.3.21.9.2.21.9.2.31.9.2.11.9.1.61.8.8.21.8.1.31.7.5.51.6.0.21.5.91.4.8.11.4.8Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-2.0.0.1 | WPForms <= 2.0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via OptinMonster Integration data-sitekey Attribute in Post Content | July 20, 2026 | 2.0.0.2 | Medium |
*-1.10.2 | WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name | June 30, 2026 | 1.10.2.1 | Medium |
*-1.10.0.4 | WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint | June 5, 2026 | 1.10.0.5 | Medium |
*-1.10.0.4 | WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More <= 1.10.0.4 - Missing Authorization | May 28, 2026 | 1.10.0.5 | Medium |
*-1.10.0.2 | Contact Form by WPForms <= 1.10.0.2 - Cross-Site Request Forgery | March 31, 2026 | 1.10.0.3 | Medium |
*-1.9.8.7 | WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More <= 1.9.8.7 - Unauthenticated Sensitive Information Exposure | March 23, 2026 | 1.9.9.2 | Medium |
*-1.9.9.3 | Contact Form by WPForms <= 1.9.9.3 - Missing Authorization | March 7, 2026 | 1.9.9.4 | Medium |
*-1.9.5 | WPForms Lite <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'start_timestamp' Parameter | May 9, 2025 | 1.9.5.1 | Medium |
*-1.9.3.1 | WPForms Lite <= 1.9.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameter | February 3, 2025 | 1.9.3.2 | Medium |
*-1.9.2.2 | Contact Form by WPForms <= 1.9.2.2 - Missing Authorization | January 3, 2025 | 1.9.2.3 | Medium |
1.8.4-1.9.2.1 | WPForms 1.8.4 - 1.9.2.1 - Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation | December 9, 2024 | 1.9.2.2 | High |
*-1.9.2.2 | WPForms <= 1.9.2.2 - Authenticated (Admin+) Stored Cross-Site Scripting | December 5, 2024 | 1.9.2.3 | Medium |
*-1.9.1.6 | WPForms – Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion | November 12, 2024 | 1.9.2.1 | Medium |
*-1.9.1.5 | WPForms <= 1.9.1.5 - Authenticated (Administrator+) Stored Cross-Site Scripting | November 4, 2024 | 1.9.1.6 | Medium |
*-1.8.7.2 | Contact Form by WPForms – Drag & Drop Form Builder for WordPress <= 1.8.7.2 - Unauthenticated Price Manipulation | May 1, 2024 | 1.8.8.2 | Medium |
*-1.8.1.2 | Contact Form by WPForms (Free and Premium) <= 1.8.1.2 - Reflected Cross-Site Scripting | June 20, 2023 | 1.8.1.3 | Medium |
*-1.7.5.3 | Contact Form by WPForms <= 1.7.5.3 - Authenticated (Administrator+) Arbitrary File Access via Path Traversal | September 19, 2022 | 1.7.5.5 | Medium |
[*, 1.6.0.2) | Contact Form by WPForms <= 1.6.0.1 - Cross-Site Scripting | May 21, 2020 | 1.6.0.2 | High |
[*, 1.5.9) | Contact Form by WPForms <= 1.5.8.2 - Stored Cross-Site Scripting | February 18, 2020 | 1.5.9 | Medium |
[*, 1.4.8.1) | Contact Form by WPForms <= 1.4.8 - Reflected Cross-Site Scripting | December 10, 2018 | 1.4.8.1 | High |
[*, 1.4.8) | Contact Form by WPForms – Drag & Drop Form Builder for WordPress <= 1.4.7.2 - Stored Cross-Site Scripting | September 18, 2018 | 1.4.8 | Medium |
Selected source records
Published: July 20, 2026
Published: June 30, 2026
Published: June 5, 2026
Published: May 28, 2026
Published: March 31, 2026
Published: March 23, 2026
Published: March 7, 2026
Published: May 9, 2025
Published: December 9, 2024
Published: May 21, 2020
Published: December 10, 2018
Published: September 19, 2022
Published: September 18, 2018
Published: February 18, 2020
Published: February 3, 2025
Published: June 20, 2023
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.