Wufoo Shortcode

Wufoo Shortcode has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2026.

2 independent researchers contributed these findings, one record each. Wufoo Shortcode is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.0.14.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage50%
Open

1

Fixed

1

Get automatic notifications for all Wufoo Shortcode vulnerabilities before they are exploited.

Most severe open issueCVSS 6.4CVE-2026-66643

Wufoo Shortcode <= 1.55 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv1.55

Wufoo Shortcode

wronganswersonly

Author

wronganswersonly

4.4(5)
88/100
Last Updated
2023-03-22 (4y ago)
Active Installs
10,000+
Downloads
256,041
Requires WP
2.6+
Requires PHP
0+
Tested up to
WP 6.0.14
Created
2011-08-09 (15y ago)

Allows the use of a special short code [wufoo] for embedding Wufoo forms. It’s best to grab the shortcode from the Wufoo Code Manager. Example: [wufoo username=”examples” formhash=”z7w4r7&#8243; autoresize=”true” height=”517&#8243; header=”show” ssl=”true”] For advanced users, you can pre-set Wufoo form values with an extra parameter: defaultv=”Field1=Bob&Field2=Sandwich Eater”

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C