Known vulnerabilities in the Ws Form plugin
8 security advisories have been published for the Ws Form plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Ws Form - PHP Object Injection (CVE-2026-4703) CRITICAL
- Ws Form - Broken Access Control (CVE-2025-3912) MEDIUM
- Ws Form - Cross-Site Scripting (XSS) (CVE-2024-13509) HIGH
- Ws Form - Cross-Site Scripting (XSS) (CVE-2024-10647) MEDIUM
- Ws Form - Security Vulnerability (CVE-2023-5424) MEDIUM
- Ws Form - SQL Injection (CVE-2023-52135) HIGH
- Ws Form - Cross-Site Scripting (XSS) (CVE-2022-23988) MEDIUM
- Ws Form - Cross-Site Scripting (XSS) (CVE-2022-23987) MEDIUM