A security flaw has been identified in the WS Form LITE drag-and-drop contact form plugin for WordPress, affecting all versions up to and including 1.10.80. The issue allows unauthenticated attackers to submit specially crafted form entries that can inject harmful code objects into your site’s backend systems.
This vulnerability cannot be exploited to cause harm on its own, as the affected plugin does not include the extra components attackers would need to turn the injected object into a functional attack. It only poses a risk if you have another WordPress plugin or theme installed on your site that has a related known vulnerability, often referred to as a POP chain.
If such a vulnerable third-party plugin or theme is present on your site, an attacker could use this flaw to delete files, steal sensitive data, or run unauthorized code on your site, depending on the specific vulnerability in the other tool.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-4703