CVE-2026-4703 (matched: php)

  • Monday, 24th August, 2026
  • 10:05am

A security vulnerability has been found in the WS Form LITE drag-and-drop contact form plugin for WordPress, a tool used to build custom contact forms on websites. The flaw impacts all versions of the plugin up to and including 1.10.80, and allows unauthenticated attackers (people who do not have login access to your site) to send malicious input through form submissions that can inject harmful code objects into your site.

This plugin flaw on its own cannot be used to cause harm, as there is no built-in way to exploit the injected object within the WS Form LITE plugin itself. The risk only exists if you have another WordPress plugin or theme installed on your site that contains a related weakness.

If such an additional plugin or theme is present, an attacker could combine the two flaws to delete files on your site, access sensitive data like customer information, or run unauthorized code on your site, with the exact impact depending on the specific weaknesses of the other installed plugin or theme.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-4703

« Back