VYPR

Contact Form builder with drag & drop for WordPress

by WordPress

CVEs (2)

  • CVE-2026-7052HigMay 28, 2026
    risk 0.47cvss 7.2epss 0.00

    The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'file_upload' parameter in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2025-3201MedMay 16, 2025
    risk 0.38cvss 5.9epss 0.00

    The Contact Form builder with drag & drop for WordPress WordPress plugin before 2.4.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.