Known vulnerabilities in the WPForms plugin
21 security advisories have been published for the WPForms plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- WPForms - PHP Object Injection (CVE-2026-9691) CRITICAL
- WPForms - PHP Object Injection (CVE-2026-49765) CRITICAL
- WPForms - PHP Object Injection (CVE-2026-49109) CRITICAL
- WPForms - PHP Object Injection (CVE-2026-49105) CRITICAL
- WPForms - PHP Object Injection (CVE-2026-49104) CRITICAL
- WPForms - PHP Object Injection (CVE-2026-49085) CRITICAL
- WPForms - Broken Access Control (CVE-2026-48835) HIGH
- WPForms - Broken Access Control (CVE-2026-39594) MEDIUM
- Wpforms - Security Vulnerability (CVE-2026-4986) MEDIUM
- WPForms - SQL Injection (CVE-2026-42742) HIGH
- WPForms - Cross-Site Request Forgery (CSRF) (CVE-2026-40764) HIGH
- WPForms - Broken Access Control (CVE-2026-32527) MEDIUM
- WPForms - Broken Access Control (CVE-2026-25430) MEDIUM
- WPForms - Information Disclosure (CVE-2026-25339) MEDIUM
- WPForms - Broken Access Control (CVE-2026-32446) MEDIUM
- Wpforms - Cross-Site Scripting (XSS) (CVE-2024-13403) MEDIUM
- Wpforms - Cross-Site Scripting (XSS) (CVE-2024-11223) MEDIUM
- Wpforms - Broken Access Control (CVE-2024-11205) HIGH
- Wpforms - Cross-Site Scripting (XSS) (CVE-2024-7056) LOW
- Wpforms - Cross-Site Request Forgery (CSRF) (CVE-2024-10593) MEDIUM
- Wpforms - Cross-Site Scripting (XSS) (CVE-2023-7063) HIGH