CVE-2026-4703 (matched: wordpress)

  • Monday, 24th August, 2026
  • 10:05am

A security flaw tracked as CVE-2026-4703 affects the free WS Form LITE drag-and-drop contact form plugin for WordPress, with the issue present in all versions up to and including 1.10.80. The vulnerability lets unauthenticated attackers (people who do not have login access to your WordPress dashboard) send specially crafted form submissions that can inject harmful code into your site’s backend.

This flaw cannot be exploited on its own, and will not cause any harm unless you also have another WordPress plugin or theme installed on your site that contains a related known vulnerability. There is no built-in weakness in the WS Form LITE plugin that would let attackers take advantage of this flaw on its own.

If you do have another vulnerable plugin or theme active on your site, an attacker could use this flaw to delete arbitrary files from your site, access sensitive data stored on your site, or run unauthorized code on your server, depending on the specific weakness present in the other installed tool.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-4703

« Back