SecAlerts
W

WPForms

Security Risk Profile

37
/100
low

Security Risk Score

Comprehensive risk assessment based on 30 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 11, 2020 to present

30
Total CVEs
11
Critical+High
0
Exploited
8
Unpatched

Threat Assessment

Avg CVSS
6.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
8
Critical/High
Risk Level
37/100
low
🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
2
High
9
Medium
17
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
14
2
Malicious File Upload
2
3
CRLF Injection
1
4
CSRF
1
5
Infoleak
1

Most Affected Products

1. WPForms WPForms9
2. WPForms Wpforms Wordpress9
3. WPForms Contact Form Wordpress4
4. WPForms Contact Form by WPForms3
5. WPForms WPForms Lite2

Recent Vulnerabilities

See more →
CVE-2026-18409
CVSS 7.2high

WPForms Pro <= 2.0.0.2 - Unauthenticated Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values

Aug 21, 2026🔧 No Patch
https://reddit.com/r/netsec/comments/1v3i9il/i_was_reporter_11_for_a_wpforms_paypal_webhook/
unknown

I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)

Jul 22, 2026🔧 No Patch
CVE-2026-12127
CVSS 5.3medium

WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name

Jul 1, 2026🔧 No Patch
CVE-2026-48835
CVSS 7.5high

WordPress Contact Form by WPForms plugin <= 1.10.0.4 - Broken Access Control vulnerability

Jun 15, 2026🔧 No Patch
CVE-2026-7792
CVSS 5.3medium

WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint

Jun 6, 2026🔧 No Patch
CVE-2026-25339
CVSS 6.5medium

WordPress Contact Form by WPForms plugin <= 1.9.8.7 - Sensitive Data Exposure vulnerability

Mar 25, 2026🔧 No Patch
CVE-2026-32446
CVSS 4.3EPSS 0%medium

WordPress Contact Form by WPForms plugin <= 1.9.9.3 - Broken Access Control vulnerability

Mar 13, 2026🔧 No Patch
CVE-2020-36919
CVSS 5.1medium

WPForms 1.7.8 - Cross-Site Scripting (XSS)

Jan 13, 2026🔧 No Patch
CVE-2025-11499
CVSS 9.8critical

Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent <= 1.1.32 - Unauthenticated Arbitrary File Upload

Nov 1, 2025🔧 No Patch
CVE-2025-10647
CVSS 8.8high

Embed PDF for WPForms <= 1.1.5 - Authenticated (Subscriber+) Arbitrary File Upload

Sep 19, 2025🔧 No Patch

Monitor WPForms in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.