CVE-2026-4703 (matched: wordpress)

  • Sunday, 23rd August, 2026
  • 04:05am

A vulnerability has been found in the free WS Form LITE drag-and-drop contact form plugin for WordPress, which affects all versions up to and including 1.10.80. The flaw lets unauthenticated attackers send malicious data through form submissions on your site to inject harmful code into the plugin. The plugin itself does not have the additional weakness required to exploit this flaw on its own.

This issue only poses a risk if you have another WordPress plugin or theme installed on your site that contains a related known vulnerability. If that other vulnerable tool is present, an attacker could potentially delete arbitrary files on your site, retrieve sensitive data, or run unauthorized code, with the exact impact depending on the specific weakness in the other plugin or theme.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-4703

« Back