A security flaw has been found in the WS Form LITE drag-and-drop contact form builder plugin for WordPress, a tool many site owners use to create custom contact forms without coding knowledge. This issue affects all versions of the plugin up to and including version 1.10.80.
The vulnerability allows people who do not have login access to your WordPress site to send specially crafted data through form submissions to exploit the plugin. On its own, this flaw does not cause any harm to your website.
However, if your site also has another plugin or theme installed that contains a related security weakness, an attacker could use this issue to delete files on your site, access sensitive information, or run unauthorized code on your server, depending on the other vulnerable software present.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-4703