← Back to overview

The WS Form LITE Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to and including 1.10.80. The vulnerability arises from deserialization of untrusted input from form submission meta values, allowing unauthenticated attackers to inject a PHP Object. While no known POP chain exists within the vulnerable plugin itself, the risk escalates significantly if another installed plugin or theme provides a POP chain. In such cases, attackers could potentially delete arbitrary files, retrieve sensitive data, or execute arbitrary code. The vulnerability requires no authentication to exploit, broadening the attack surface. Affected site administrators should update to a patched version immediately to mitigate risk.

Affected products

  • WS Form LITE – Drag & Drop Contact Form Builder for WordPress (versions up to and including 1.10.80)

Related CVE's

  • CVE-2026-4703

Categories

  • Web Technologies