SecAlerts
W

WPForms

Security Risk Profile

38
/100
low

Security Risk Score

Comprehensive risk assessment based on 33 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 11, 2020 to present

33
Total CVEs
11
Critical+High
0
Exploited
8
Unpatched

Threat Assessment

Avg CVSS
6.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
8
Critical/High
Risk Level
38/100
low
📈 3 in Last 30 Days

Severity Distribution

Critical
2
High
9
Medium
20
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
4

Age Distribution

Common Weaknesses (CWE)

1
XSS
15
2
Malicious File Upload
2
3
Code Injection
1
4
CRLF Injection
1
5
CSRF
1

Most Affected Products

1. WPForms WPForms10
2. WPForms Wpforms Wordpress9
3. WPForms Contact Form Wordpress4
4. WPForms WPForms Lite3
5. WPForms Contact Form by WPForms3

Recent Vulnerabilities

See more →
CVE-2026-84744
CVSS 6.5medium

WPForms Lite 1.5.0.1 - 2.0.2 - Unauthenticated Arbitrary Shortcode Execution via Form Field Repopulation

Sep 28, 2026🔧 No Patch
CVE-2026-88996
CVSS 6.1medium

WPForms <= 2.0.2 - Reflected Cross-Site Scripting via 'page_title' POST Parameter

Sep 25, 2026🔧 No Patch
CVE-2026-74991
CVSS 6.8medium

WPForms Lite 1.8.8.2 - 2.0.1.1 - Unauthenticated Stripe Refund and Subscription Cancellation via External PaymentIntent

Sep 24, 2026🔧 No Patch
CVE-2026-18409
CVSS 7.2high

WPForms Pro <= 2.0.0.2 - Unauthenticated Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values

Aug 21, 2026🔧 No Patch
https://reddit.com/r/netsec/comments/1v3i9il/i_was_reporter_11_for_a_wpforms_paypal_webhook/
unknown

I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)

Jul 22, 2026🔧 No Patch
CVE-2026-12127
CVSS 5.3medium

WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name

Jul 1, 2026🔧 No Patch
CVE-2026-48835
CVSS 7.5high

WordPress Contact Form by WPForms plugin <= 1.10.0.4 - Broken Access Control vulnerability

Jun 15, 2026🔧 No Patch
CVE-2026-7792
CVSS 5.3medium

WPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook Endpoint

Jun 6, 2026🔧 No Patch
CVE-2026-25339
CVSS 6.5medium

WordPress Contact Form by WPForms plugin <= 1.9.8.7 - Sensitive Data Exposure vulnerability

Mar 25, 2026🔧 No Patch
CVE-2026-32446
CVSS 4.3EPSS 0%medium

WordPress Contact Form by WPForms plugin <= 1.9.9.3 - Broken Access Control vulnerability

Mar 13, 2026🔧 No Patch

Monitor WPForms in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.