Skip to main content

Vendor/product archive

weformspro / weforms CVEs

Beta · best-effort

6 CVEs tagged to weformspro / weforms1 Critical, 1 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2023-51524

Published Jun 12, 2024

Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.18.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-30512

Published Jun 9, 2024

Missing Authorization vulnerability in weForms.This issue affects weForms: from n/a through 1.6.20.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-0386

Published Mar 12, 2024

The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versions up to, and including, 1.6.21 due to insufficient input…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50896

Published Dec 29, 2023

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weForms weForms – Easy Drag & Drop Contact Form Builder For WordPress allows…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-2395

Published Aug 8, 2022

The weForms WordPress plugin before 1.6.14 does not sanitise and escape its settings, allowing high privilege users such as admin to perform cross-Site Scripting attacks even when…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1