SecAlerts
WPForms logo

WPForms

Security Risk Profile

35
/100
low

Security Risk Score

Comprehensive risk assessment based on 29 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 11, 2020 to present

29
Total CVEs
10
Critical+High
0
Exploited
7
Unpatched

Threat Assessment

Avg CVSS
6.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
7
Critical/High
Risk Level
35/100
low
📈 1 in Last 30 Days

Severity Distribution

Critical
2
High
8
Medium
17
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
13
2
Malicious File Upload
2
3
CRLF Injection
1
4
CSRF
1
5
Infoleak
1

Most Affected Products

1. WPForms WPForms9
2. WPForms Wpforms Wordpress9
3. WPForms Contact Form Wordpress4
4. WPForms Contact Form by WPForms3
5. WPForms WPForms Lite2

Recent Vulnerabilities

See more →
https://reddit.com/r/netsec/comments/1v3i9il/i_was_reporter_11_for_a_wpforms_paypal_webhook/
unknown

I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)

7/22/2026🔧 No Patch
CVE-2026-12127
CVSS 5.3medium

WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name

7/1/2026🔧 No Patch
CVE-2026-48835
CVSS 7.5high

WordPress Contact Form by WPForms plugin <= 1.10.0.4 - Broken Access Control vulnerability

6/15/2026🔧 No Patch
CVE-2026-7792
CVSS 5.3medium

WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint

6/6/2026🔧 No Patch
CVE-2026-25339
CVSS 6.5medium

WordPress Contact Form by WPForms plugin <= 1.9.8.7 - Sensitive Data Exposure vulnerability

3/25/2026🔧 No Patch
CVE-2026-32446
CVSS 4.3EPSS 0%medium

WordPress Contact Form by WPForms plugin <= 1.9.9.3 - Broken Access Control vulnerability

3/13/2026🔧 No Patch
CVE-2020-36919
CVSS 5.1medium

WPForms 1.7.8 - Cross-Site Scripting (XSS)

1/13/2026🔧 No Patch
CVE-2025-11499
CVSS 9.8critical

Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent <= 1.1.32 - Unauthenticated Arbitrary File Upload

11/1/2025🔧 No Patch
CVE-2025-10647
CVSS 8.8high

Embed PDF for WPForms <= 1.1.5 - Authenticated (Subscriber+) Arbitrary File Upload

9/19/2025🔧 No Patch
CVE-2025-3794
CVSS 5.4medium

WPForms Lite <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'start_timestamp' Parameter

5/9/2025🔧 No Patch

Monitor WPForms in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.