A security flaw has been identified in the WS Form LITE drag-and-drop contact form builder plugin for WordPress, a tool used to create custom forms on websites. The flaw impacts all versions of the plugin up to and including version 1.10.80, and stems from how the plugin handles data submitted through your site’s forms.
This specific vulnerability cannot be exploited on its own. It only poses a risk if your WordPress site also has another plugin or theme installed that contains a separate related vulnerability (called a POP chain). If that additional vulnerable software is present on your site, an unauthenticated attacker (someone who does not need a login to your site) could use this flaw to delete files, access sensitive information, or run unauthorized code, with the exact impact depending on the specific vulnerability in the other installed software.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-4703