Pricing
Case studies
Login
Start trial
Contact Form by WPForms
Syed Balkhi
Developer
1.10.0.2
Latest version
6,000,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
16 patched
1 Mitigation rules
Sensitive Data Exposure vulnerability
<= 1.9.8.7
23/03/2026
Broken Access Control vulnerability
<= 1.9.9.3
07/03/2026
Authenticated (Contributor+) Stored Cross-Site Scripting via 'start_timestamp' Parameter vulnerability
<= 1.9.5
09/05/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via fieldHTML Parameter vulnerability
<= 1.9.3.1
03/02/2025
Broken Access Control vulnerability
<= 1.9.2.2
03/01/2025
Admin+ Stored XSS vulnerability
< 1.9.2.3
26/12/2024
Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation vulnerability
1.8.4-1.9.2.1
09/12/2024
Admin+ Stored XSS vulnerability
< 1.9.1.6
25/11/2024
Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion vulnerability
<= 1.9.1.6
12/11/2024
Unauthenticated Price Manipulation vulnerability
<= 1.8.7.2
02/05/2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 1.8.1.2
20/06/2023
Authenticated Arbitrary File Access vulnerability
<= 1.7.5.3
19/09/2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 1.6.0.1
01/07/2020
Authenticated Cross-Site Scripting (XSS) vulnerability
<= 1.5.8.2
05/03/2020
Unauthenticated Cross-Site Scripting (XSS) vulnerability
<= 1.4.8
10/12/2018
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 1.4.7
07/12/2018