MachForm Shortcode
MachForm Shortcode has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for MachForm Shortcode has a vendor fix available, so running the current release closes it.
All of these findings were reported by SOPROBRO. MachForm Shortcode is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-24636MachForm Shortcode <= 1.4.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records

MachForm Shortcode
Author
Laymance Technologies
MachForms is an excellent, easy to use form builder that you host on your own server or site. Embedding one of those forms in WordPress used to mean “jumping through some hoops”. Not any more. Add a form with the MachForm block in the block editor (Gutenberg): insert the block, type your form’s ID, and you are done. Prefer shortcodes, or working in the classic editor or a page builder? The [machform] shortcode does exactly the same job and both produce identical markup. Need a form in a blog post? On a page? In a widget area? No problem. For more information, check out the plugin page on our website. Features include: A MachForm block for the block editor, so you can add a form without writing a shortcode Support for MachForm’s modern javascript forms, with no jQuery needed Support for MachForm’s older jQuery based forms Support for iframe based forms Support for URL Parameters Easy to use! This plugin isn’t just for developers, no matter what your skill level you can use this plugin to easily add forms from your MachForms system to your website! How to use the block editor block: Click the “Code” option on your form inside of MachForm to see the embed codes, and make note of your form’s “ID” and “height”. In the block editor, add a block and search for “MachForm”. Enter your form’s ID. Height, title, embed method and URL parameters are all in the block sidebar. You are done! The form appears on the published page. The editor shows a summary card rather than a live form, so the form cannot resize itself while you are editing around it. How to use the shortcode: Click the “Code” option on your form inside of MachForm to see the embed codes. Make note of your form’s “ID” and the “height”. Use the shortcode to embed your form into your content using this format: [machform id=(ID #) height=(height #)] You are done, your form should show in your content now! The shortcode and the block produce exactly the same markup, so you can use whichever suits you and mix them freely. Embed methods: type=js – the default. Automatically uses the modern method if your MachForm supports it, and the jQuery method if it does not. You normally do not need to think about this. type=mf – forces MachForm’s modern javascript loader (js/mf.js). One script, no jQuery, and the form resizes itself to fit. type=jquery – forces the older jQuery loader. Only needed if your MachForm is too old to include js/mf.js. type=iframe – a plain iframe with no javascript. Fixed height, but you can use as many on one page as you like. URL Parameters: The plugin now supports URL parameters. The parameters are easy to pass via the shortcode by simply including the parameter and value inside of the shortcode like the following example: [machform type=js id=1593 height=703 element_1_1=”Field Text Here” element_1_2=”Field Text Here”] For more information on using URL Parameters with MachForm, please see their website by clicking here. Review or Rating Don’t forget to leave a review or a rating, and also connect with us on social media! Thank you for your support. IMPORTANT NOTE: MachForms is a 3rd party application sold by AppNitro. Installing this plugin allows you to use a shortcode anywhere on your site to embed a form that is created in MachForms. This plugin does not provide a form builder interface.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C