What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WS Form WS Form LITE – Drag & Drop Contact Form Builder for WordPress.This issue affects WS Form LITE – Drag & Drop Contact Form Builder for WordPress: from n/a through 1.9.170.
Explanation of Vulnerability in Simple Terms
02Summary
WS Form LITE versions up to 1.9.170 contain a SQL injection vulnerability in the form processing logic. An authenticated administrator can craft malicious input that executes arbitrary SQL queries against the site database. This allows reading sensitive data like user credentials and form submissions, or degrading database performance. Update to a version newer than 1.9.170.
What an attacker can do
03Attacker Capabilities
Read sensitive database records or degrade database performance via SQL injection.
Potential impact on your site
04Site Impact
Unauthorized access to user data, form submissions, and credentials stored in the database.
Conditions required to exploit
05Prerequisites
Attacker must have administrator privileges on the WordPress site.
Key dates
06Disclosure timeline
December 29, 2023
CVE published
April 28, 2026
Record updated