Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-4703: WS Form LITE lets strangers inject code via forms

CVE-2026-4703 · published 12 days ago
Summary

The WS Form LITE contact‑form plugin for WordPress can accept specially crafted data when a form is submitted, allowing anyone on the internet to insert a malicious object into the site’s code. By itself this does not do anything harmful, but if the site also runs another plugin or theme that contains a dangerous code sequence, an attacker could then delete files, steal data, or run commands. Update the plugin to the latest version or remove it, and review installed plugins for risky code.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
westguard ws form lite – drag & drop contact form builder <= 1.10.80
Original advisory text
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input f...
The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published22 Aug 2026
Updated3 Sep 2026
First seen22 Aug 2026
Sources
CVE-2026-4703 · NVD
CVE-2026-4703 · MITRE
Monitor software like this
Free during beta