CVE-2026-4703 (matched: wordpress)

  • Monday, 24th August, 2026
  • 04:05am

A security flaw has been found in the WS Form LITE drag-and-drop contact form builder plugin for WordPress, a popular tool for adding custom contact forms to websites without coding experience. The flaw impacts all versions of the plugin up to 1.10.80, and allows unauthenticated attackers (people who do not have access to your site’s admin area) to send harmful PHP objects through data submitted via your contact forms. This flaw on its own does not create direct risk, as there is no built-in way for attackers to exploit it further using only the form plugin itself. However, if your WordPress site also has another plugin or theme installed that contains a related known vulnerability, attackers can chain the two flaws together to cause harm. If that secondary vulnerability exists, attackers may be able to delete files from your site, access sensitive data like customer information or admin login credentials, or run unauthorized code on your site, depending on what the other vulnerable plugin or theme allows them to do.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-4703

« Back