WordPress Plugin Vulnerabilities

WPForms < 1.9.9.2 - Unauthenticated Sensitive Information Exposure

Description

The plugin is vulnerable to Sensitive Information Exposure. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

Affects Plugins

Fixed in 1.9.9.2

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Sandeep V
Verified
No

Timeline

Publicly Published
2026-03-23 (about 1 month ago)
Added
2026-04-02 (about 1 month ago)
Last Updated
2026-04-02 (about 1 month ago)

Other