CVE-2020-10385: Wpforms Contact Form

Medium severity, CVSS 5.4. EPSS: 4.4% chance of exploitation in the next 30 days.

A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.

Affected products

  • Wpforms Contact Form: before 1.5.9 (fixed in 1.5.9)

Published 2020-03-24. Last modified 2026-06-17.