A security flaw has been found in the WS Form LITE drag-and-drop contact form plugin for WordPress, which impacts all versions up to and including 1.10.80. The vulnerability allows people who don’t have login access to your WordPress site to inject harmful code into your site’s server by submitting specially crafted entries through forms built with this plugin.
This flaw cannot be exploited on its own to cause damage, as there is no built-in weakness in the WS Form LITE plugin that would let an attacker take action with the injected code. It only poses a risk if you also have another WordPress plugin or theme installed on your site that contains a related exploitable weakness. If that additional vulnerable plugin or theme is present, an attacker could use this flaw to delete files on your site, access sensitive private data, or run unauthorized code on your hosting server, depending on the specific weakness in the other installed tool.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-4703