| CVE-2025-26544 | WordPressUTM tags + Landing page plugin <= 1.4 - CSRF to Stored XSS vulnerability | Max K | UTM tags tracking for Contact Form 7 | High | 7.1 | 2025-03-26 14:24:19 | Deep Dive |
| CVE-2024-11273 | Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSS | Unknown | Contact Form & SMTP Plugin for WordPress by PirateForms | 中危 | - | 2025-03-25 06:00:10 | Deep Dive |
| CVE-2024-11272 | Contact Form & SMTP Plugin for WordPress by PirateForms < 2.6.0 - Admin+ Stored XSS | Unknown | Contact Form & SMTP Plugin for WordPress by PirateForms | 中危 | - | 2025-03-25 06:00:10 | Deep Dive |
| CVE-2024-10560 | Form Maker by 10Web < 1.15.30 - Admin+ Stored XSS | Unknown | Form Maker by 10Web | 低危 | - | 2025-03-25 06:00:07 | Deep Dive |
| CVE-2025-30620 | WordPress WP Odoo Form Integrator plugin <=1.1.0 - CSRF to Stored XSS vulnerability | coderscom | WP Odoo Form Integrator | High | 7.1 | 2025-03-24 13:47:33 | Deep Dive |
| CVE-2025-30522 | WordPress Contact Form 7 Material Design plugin <= 1.0.0 - CSRF to Stored XSS vulnerability | Damian Orzol | Contact Form 7 Material Design | High | 7.1 | 2025-03-24 13:46:37 | Deep Dive |
| CVE-2024-10558 | Form Maker by 10Web < 1.15.30 - Admin+ Stored XSS | Unknown | Form Maker by 10Web | - | - | 2025-03-24 06:00:06 | Deep Dive |
| CVE-2024-13666 | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing | techjewel | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Medium | 5.3 | 2025-03-22 08:24:18 | Deep Dive |
| CVE-2025-1530 | Tripetto <= 8.0.9 - Cross-Site Request Forgery to Arbitrary Results Deletion | tripetto | WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto | Medium | 4.3 | 2025-03-15 11:13:29 | Deep Dive |
| CVE-2024-13497 | WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto <= 8.0.9 - Unauthenticated Stored Cross-Site Scripting | tripetto | WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto | High | 7.2 | 2025-03-15 04:22:08 | Deep Dive |
| CVE-2024-13498 | NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.8.1 - Unauthenticated Sensitive Information Exposure | webaways | NEX-Forms – Ultimate Forms Plugin for WordPress | Medium | 5.3 | 2025-03-12 05:22:52 | Deep Dive |
| CVE-2025-28914 | WordPress wordpress login form to anywhere plugin <= 0.2 - Cross Site Scripting (XSS) vulnerability | Ajay Sharma | wordpress login form to anywhere | Medium | 5.9 | 2025-03-11 21:01:00 | Deep Dive |
| CVE-2025-28902 | WordPress Contact Form 7 Select Box Editor Button plugin <= 0.6 - Cross Site Request Forgery (CSRF) vulnerability | Benjamin Pick | Contact Form 7 Select Box Editor Button | Medium | 4.3 | 2025-03-11 21:00:53 | Deep Dive |
| CVE-2025-28864 | WordPress Builder for Contact Form 7 by Webconstruct plugin <= 1.2.2 - Cross Site Request Forgery (CSRF) vulnerability | planetstudio | Builder for Contact Form 7 by Webconstruct | Medium | 4.3 | 2025-03-11 21:00:35 | Deep Dive |
| CVE-2025-1463 | Spreadsheet Integration <= 3.8.2 - Cross-Site Request Forgery to Arbitrary Post Publish | javmah | WPGSI: Spreadsheet Integration | Medium | 4.3 | 2025-03-05 11:22:08 | Deep Dive |
| CVE-2025-26994 | WordPress Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin <= 7.4.2 - Cross Site Scripting (XSS) vulnerability | softdiscover | Zigaform – Price Calculator & Cost Estimation Form Builder Lite | High | 7.1 | 2025-03-03 13:30:42 | Deep Dive |
| CVE-2025-23736 | WordPress Form To JSON plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability | webgdawg | Form To JSON | High | 7.1 | 2025-03-03 13:30:17 | Deep Dive |
| CVE-2024-12544 | SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity <= 1.12.17 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion via SurveyJS_DeleteFile | devsoftbaltic | SurveyJS: Drag & Drop Form Builder | High | 8.8 | 2025-03-01 07:24:06 | Deep Dive |
| CVE-2024-8420 | DHVC Form <= 2.4.7 - Unauthenticated Privilege Escalation | SiteSao | DHVC Form | Critical | 9.8 | 2025-02-28 08:23:19 | Deep Dive |
| CVE-2025-1511 | User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.0.4 - Reflected Cross-Site Scripting | wpeverest | User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder | Medium | 6.1 | 2025-02-28 05:23:14 | Deep Dive |