CVE-2020-10385: Wpforms Contact Form
Medium severity, CVSS 5.4. EPSS: 4.4% chance of exploitation in the next 30 days.
A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.
Affected products
- Wpforms Contact Form: before 1.5.9 (fixed in 1.5.9)
Published 2020-03-24. Last modified 2026-06-17.