A security flaw has been found in the WS Form LITE drag-and-drop contact form builder plugin for WordPress, a tool used to create custom contact forms on websites. The flaw impacts all versions of the plugin up to and including 1.10.80, and allows people who do not have login access to your site to inject harmful code objects through data submitted via your contact forms.
On its own, this specific plugin flaw cannot be used to cause damage, as there is no built-in path for attackers to exploit the injected code. However, if you have other WordPress plugins or themes installed that contain a related weakness, an attacker could leverage this flaw to take dangerous actions, including deleting files from your site, stealing sensitive private data, or running unauthorized code on your site.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-4703