A security vulnerability has been found in the WS Form LITE drag-and-drop contact form builder plugin for WordPress, impacting all versions up to 1.10.80. The flaw allows unauthenticated visitors to your site (people who do not have a login for your WordPress dashboard) to send malicious input through form submissions that can inject harmful code into your site's internal systems.
This specific vulnerability cannot be exploited on its own, as the WS Form LITE plugin does not include the additional code attackers would need to turn this flaw into a working attack. It only creates a risk if you have another WordPress plugin or theme installed on your site that has its own related security gap.
If that other plugin or theme does have that related gap, attackers could combine the two flaws to delete files on your site, steal sensitive information (such as customer data or admin account credentials), or run unauthorized code on your site, with the exact impact depending on the specific gap present in the other installed tool.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-4703