Formstack Online Forms
Formstack Online Forms has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Formstack Online Forms has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Legion Hunter. Formstack Online Forms is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.1.24.
CVE-2025-62738Formstack Online Forms <= 2.0.2 - Missing Authorization
Read the full analysisVulnerability Records

Formstack Online Forms
Author
mmattax
Formstack’s WordPress form plugin makes it quick and easy to embed contact forms, lead generation forms, payment forms, and more on your WordPress blogs and websites. Build customized online forms in seconds with our drag-and-drop interface, and integrate with 40+ third-party apps, including Salesforce, MailChimp, and PayPal. This plugin features two components: Formstack Widget Formstack Plugin The Formstack widget allows you to embed Formstack web forms into your sidebar. The widget automatically optimizes the web form’s CSS to make your online forms fit and look great on your WordPress pages. The Formstack Plugin adds a button to the TinyMCE editor that allows you to easily select the Formstack web form you wish to embed. Once a form is selected, a shortcode will be inserted into the editor, which will be converted to the selected form once your page or blog post is rendered. This plugin supports the following shortcodes [Formstack], [formstack], and [fs]. A Formstack account and API key are required. Signup for free today!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C