CVE-2022-50959: Wpdevart Contact Form Builder
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
WordPress Contact Form Builder 1.6.1 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by exploiting the form_id parameter. Attackers can craft malicious URLs to code_generator.php with script payloads in the form_id parameter to execute arbitrary JavaScript in victim browsers.
Affected products
- Wpdevart Contact Form Builder: version 1.6.1 only
Published 2026-05-10. Last modified 2026-07-24.