Forms

Forms has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2025; all 3 are fixed as of September 2026. Their average CVSS score is 8.0, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 1 high.

The most common weakness is Unrestricted Upload Of File With Dangerous Type, behind 2 of the records (67%). Other recurring categories include Cross-Site Scripting.

Every one of the 3 issues recorded for Forms has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. Forms is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSHigh
8.0/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all Forms vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2024-51791

Forms <= 2.8.0 - Unauthenticated Arbitrary File Upload

Read the full analysis

Vulnerability Records

3 records
Forms banner
Latestv3.0.1
5.0(1)
100/100
Last Updated
2026-06-08 (3mo ago)
Active Installs
100+
Downloads
6,375
Requires WP
5.0+
Requires PHP
8.5+
Tested up to
WP 6.9.7
Created
2016-08-16 (10y ago)

Forms is an easy form manager that lets you manage all your cool forms. Creating your own contact form or newsletter subscriber is easy. Docs & Support You can find docs, FAQ and more detailed information about Forms on madeit.be. If you were unable to find the answer to your question on the FAQ or in any of the documentation, you should check the support forum on WordPress.org or GitHub. If you can’t locate any topics that pertain to your particular issue, post a new topic for it. Recommended Plugins The following plugins are working with Forms: Translations You can translate Forms on translate.wordpress.org.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C