| CVE-2024-1400 | Mollie Forms <= 2.6.3 - Missing Authorization to Arbitrary Post Duplication | ndijkstra | Mollie Forms | Medium | 4.3 | 2024-03-11 21:30:58 | Deep Dive |
| CVE-2024-1645 | Mollie Forms <= 2.6.3 - Missing Authorization | ndijkstra | Mollie Forms | Medium | 4.3 | 2024-03-11 21:30:57 | Deep Dive |
| CVE-2024-1169 | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization to Unauthenticated Media Upload | themekraft | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) | High | 7.5 | 2024-03-07 11:01:58 | Deep Dive |
| CVE-2024-1170 | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization to Unauthenticated Media Deletion | themekraft | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) | High | 8.2 | 2024-03-07 11:01:58 | Deep Dive |
| CVE-2023-7203 | Smart Forms < 2.6.87 - Subscriber+ Arbitrary Entry Deletion | Unknown | Smart Forms | 中危 | - | 2024-02-27 08:30:25 | Deep Dive |
| CVE-2024-1218 | Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization | wpchill | Kali Forms — Contact Form & Drag-and-Drop Builder | Medium | 4.3 | 2024-02-20 18:56:50 | Deep Dive |
| CVE-2024-1217 | Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization to Arbitrary Plugin Deactivation | wpchill | Kali Forms — Contact Form & Drag-and-Drop Builder | High | 7.6 | 2024-02-20 18:56:35 | Deep Dive |
| CVE-2023-5665 | Payment Forms for Paystack <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | kendysond | Payment Forms for Paystack | Medium | 6.4 | 2024-02-08 03:33:15 | Deep Dive |
| CVE-2024-24771 | Open Forms potential multi-factor authentication bypass | open-formulieren | open-forms | High | 7.7 | 2024-02-07 14:51:10 | Deep Dive |
| CVE-2023-6953 | PDF Generator For Fluent Forms <= 1.1.7 - Cross-Site Scripting | wpmanageninja | Fluent PDF Generator | Medium | 4.9 | 2024-02-05 21:21:59 | Deep Dive |
| CVE-2024-0660 | Formidable Forms <= 6.7.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting | strategy11team | Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder | Medium | 6.1 | 2024-02-05 21:21:59 | Deep Dive |
| CVE-2024-1121 | Advanced Forms for ACF <= 1.9.3.2 - Missing Authorization to Unauthenticated Form Settings Export | philkurth | Advanced Forms for ACF | Medium | 5.3 | 2024-02-05 21:21:52 | Deep Dive |
| CVE-2024-0324 | User Profile Builder <= 3.10.8 - Missing Authorization to Plugin Settings Change via wppb_two_factor_authentication_settings_update | cozmoslabs | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | High | 8.2 | 2024-02-05 21:21:37 | Deep Dive |
| CVE-2024-0685 | Ninja Forms Contact Form <= 3.7.1 - Unauthenticated Second Order SQL Injection | kstover | Ninja Forms – The Contact Form Builder That Grows With You | Medium | 5.9 | 2024-02-02 04:32:35 | Deep Dive |
| CVE-2023-51509 | WordPress RegistrationMagic Plugin <= 5.2.4.1 is vulnerable to Cross Site Scripting (XSS) | Metagauss | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | High | 7.1 | 2024-02-01 11:24:54 | Deep Dive |
| CVE-2023-51695 | WordPress Everest Forms Plugin <= 2.0.4.1 is vulnerable to Cross Site Scripting (XSS) | WPEverest | Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease! | Medium | 5.9 | 2024-02-01 11:07:21 | Deep Dive |
| CVE-2023-51536 | WordPress CRM Perks Forms Plugin <= 1.1.2 is vulnerable to Cross Site Scripting (XSS) | CRM Perks | CRM Perks Forms – WordPress Form Builder | Medium | 5.9 | 2024-02-01 10:25:54 | Deep Dive |
| CVE-2023-52192 | WordPress Keap Official Opt-in Forms Plugin <= 1.0.11 is vulnerable to Cross Site Scripting (XSS) | Keap | Keap Official Opt-in Forms | Medium | 6.5 | 2024-02-01 09:52:18 | Deep Dive |
| CVE-2024-1129 | NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via set_starred() | webaways | NEX-Forms – Ultimate Forms Plugin for WordPress | Medium | 5.3 | 2024-02-01 04:31:55 | Deep Dive |
| CVE-2024-1130 | NEX-Forms – Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via set_read() | webaways | NEX-Forms – Ultimate Forms Plugin for WordPress | Medium | 5.3 | 2024-02-01 04:31:55 | Deep Dive |