| CVE-2024-2782 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Setting Manipulation | techjewel | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | High | 7.5 | 2024-05-18 07:38:33 | Deep Dive |
| CVE-2024-2771 | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.16 - Missing Authorization to Settings Update and Limited Privilege Escalation | techjewel | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | Critical | 9.8 | 2024-05-18 07:38:21 | Deep Dive |
| CVE-2024-34755 | WordPress Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin <= 1.3.9 - Cross Site Request Forgery (CSRF) vulnerability | CRM Perks | Integration for Contact Form 7 and Salesforce | Medium | 4.3 | 2024-05-17 09:52:40 | Deep Dive |
| CVE-2024-34756 | WordPress Integration for HubSpot and Contact Form 7 plugin <= 1.3.1 - Cross Site Request Forgery (CSRF) vulnerability | CRM Perks | Integration for Contact Form 7 HubSpot | Medium | 4.3 | 2024-05-17 09:49:30 | Deep Dive |
| CVE-2024-30540 | WordPress VS Contact Form plugin <= 14.7 - Sum Captcha Bypass vulnerability | Guido | VS Contact Form | Medium | 5.3 | 2024-05-17 08:20:24 | Deep Dive |
| CVE-2023-23990 | WordPress Redirection for Contact Form 7 plugin <= 2.7.0 - Privilege Escalation vulnerability | Qube One Ltd. | Redirection for Contact Form 7 | High | 7.6 | 2024-05-17 06:33:39 | Deep Dive |
| CVE-2024-4144 | Simple Basic Contact Form <= 20240502 - Unauthenticated Arbitrary Shortcode Execution | wpkube | Simple Basic Contact Form | Medium | 6.5 | 2024-05-14 05:33:00 | Deep Dive |
| CVE-2024-34817 | WordPress Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms plugin <= 1.2.0 - Cross Site Request Forgery (CSRF) vulnerability | CRM Perks | Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms | Medium | 4.3 | 2024-05-10 08:35:23 | Deep Dive |
| CVE-2024-4150 | Simple Basic Contact Form <= 20221201 - Reflected Cross-Site Scripting | wpkube | Simple Basic Contact Form | Medium | 6.1 | 2024-05-09 20:03:21 | Deep Dive |
| CVE-2024-3637 | Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Admin+ Stored XSS | Unknown | Responsive Contact Form Builder & Lead Generation Plugin | - | - | 2024-05-03 06:00:02 | Deep Dive |
| CVE-2024-1415 | Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Cross-Site Request Forgery | themehunk | Lead Form Builder & Contact Form | Medium | 4.3 | 2024-05-02 16:52:45 | Deep Dive |
| CVE-2024-1416 | Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Missing Authorization | themehunk | Lead Form Builder & Contact Form | Medium | 4.3 | 2024-05-02 16:52:42 | Deep Dive |
| CVE-2024-3715 | Database for Contact Form 7, WPforms, Elementor forms <= 1.3.8 - Unauthenticated Stored Cross-Site Scripting | crmperks | Database for Contact Form 7, WPforms, Elementor forms | High | 7.2 | 2024-05-02 16:52:31 | Deep Dive |
| CVE-2024-3870 | Contact Form 7 Database Addon – CFDB7 <= 1.2.6.8 - Unauthenticated Sensitive Information Exposure | arshidkv12 | Database Addon for Contact Form 7 – CFDB7 | Medium | 5.3 | 2024-05-02 16:52:26 | Deep Dive |
| CVE-2024-2542 | Jotform Online Forms <= 1.3.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode | jotform | Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform | Medium | 6.4 | 2024-05-02 16:52:25 | Deep Dive |
| CVE-2024-3649 | Contact Form by WPForms – Drag & Drop Form Builder for WordPress <= 1.8.7.2 - Unauthenticated Price Manipulation | smub | WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More | Medium | 5.3 | 2024-05-02 16:52:13 | Deep Dive |
| CVE-2024-0847 | 5280 Bootstrap Modal Contact Form <= 1.0 - Cross-Site Request Forgery to Bulk Delete Messages | 5280studios | 5280 Bootstrap Modal Contact Form | Medium | 4.3 | 2024-05-02 16:51:50 | Deep Dive |
| CVE-2024-3717 | Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.7.7 - Sensitive Information Exposure | glenwpcoder | Drag and Drop Multiple File Upload for Contact Form 7 | Medium | 5.3 | 2024-05-02 16:51:48 | Deep Dive |
| CVE-2024-3585 | Send PDF for Contact Form 7 <= 1.0.2.3 - Missing Authorization | florent73 | Send PDF for Contact Form 7 | Medium | 5.3 | 2024-05-02 16:51:43 | Deep Dive |
| CVE-2024-1945 | ARForms Form Builder <= 1.6.4 - Missing Authorization to Authenticated(Subscriber+) Arbitrary Option Deletion | reputeinfosystems | Contact Form, Survey, Quiz & Popup Form Builder – ARForms | High | 7.1 | 2024-05-02 16:51:41 | Deep Dive |