A security issue tracked as CVE-2026-4703 affects the free WS Form LITE drag-and-drop contact form builder plugin for WordPress. All versions of the plugin up to and including version 1.10.80 have this flaw.
The issue exists because the plugin does not safely handle data submitted through the contact forms it creates. This allows attackers who do not have any login access to your website to send specially crafted data that can inject harmful objects into your site's backend system.
This flaw on its own does not cause harm, as there is no existing vulnerability in the WS Form LITE plugin that would let attackers use these injected objects for damage. It only becomes a risk if you have another WordPress plugin or theme installed that has a related security weakness. If that is the case, attackers could exploit this flaw to delete files on your site, steal sensitive private data, or run unauthorized code on your site, depending on what that other plugin or theme allows.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-4703