← Back

Contact Form & Lead Form Elementor Builder

contact_form_&_lead_form_elementor_builder

Vendor: Themehunk • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Themehunk
1Contact Form & Lead Form Elementor Builder
Jun 9, 2025
May 15, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin before 1.9.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-S...Show more
The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin before 1.9.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).Show less
1Themehunk
1Contact Form & Lead Form Elementor Builder
May 8, 2025
May 3, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin through 1.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-...Show more
The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin through 1.8.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)Show less
1Themehunk
1Contact Form & Lead Form Elementor Builder
Jun 16, 2025
Jan 16, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various setting...Show more
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settingsShow less
1Themehunk
1Contact Form & Lead Form Elementor Builder
May 9, 2025
Jan 16, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scri...Show more
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowedShow less
1Themehunk
1Contact Form & Lead Form Elementor Builder
Nov 21, 2024
Dec 27, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged i...Show more
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.6.4 does not sanitise and escape some lead values, which could allow unauthenticated users to perform Cross-Site Scripting attacks against logged in admin viewing the inserted LeadsShow less