Announcements

CVE-2026-4703 (matched: php)

  • 24th August 2026
A security vulnerability has been found in the WS Form LITE drag-and-drop contact form plugin for WordPress, a tool used to build custom contact forms on websites. The flaw impacts all versions of the plugin up to and including 1.10.80, and allows unauthenticated attackers (people who do not have login access to your site) to send malicious input ...
Continue reading

CVE-2026-4703 (matched: wordpress)

  • 24th August 2026
A security flaw tracked as CVE-2026-4703 affects the free WS Form LITE drag-and-drop contact form plugin for WordPress, with the issue present in all versions up to and including 1.10.80. The vulnerability lets unauthenticated attackers (people who do not have login access to your WordPress dashboard) send specially crafted form submissions that ...
Continue reading