A security flaw has been found in the WS Form LITE drag-and-drop contact form builder plugin for WordPress, affecting all versions up to and including 1.10.80. The issue exists because the plugin does not safely process data submitted through its contact forms, which could allow attackers who are not logged into your WordPress site to send harmful input to your website.
This specific flaw does not cause damage on its own, as there is no built-in weakness in the WS Form LITE plugin that attackers can exploit directly. It only becomes a risk if you have another WordPress plugin or theme installed on your site that has a related coding flaw. If such a flaw is present, an attacker could use this vulnerability to delete files on your site, access sensitive information, or run unauthorized code, with the exact impact depending on the nature of the related flaw in the other installed tool.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-4703