What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in kamleshyadav Pixel WordPress Form BuilderPlugin & Autoresponder pixel-formbuilder allows Cross Site Request Forgery.This issue affects Pixel WordPress Form BuilderPlugin & Autoresponder: from n/a through <= 1.0.3.
Explanation of Vulnerability in Simple Terms
02Summary
The Pixel WordPress Form Builder plugin through version 1.0.3 is vulnerable to cross-site request forgery (CSRF). An attacker can trick a logged-in site administrator into performing unintended actions, such as modifying form settings or creating malicious forms. The vulnerability requires the admin to visit a malicious webpage while authenticated to the WordPress site.
What an attacker can do
03Attacker Capabilities
Trick an authenticated admin into modifying forms or site settings without their knowledge.
Potential impact on your site
04Site Impact
An attacker could alter your forms, change autoresponder settings, or inject malicious content into form submissions.
Conditions required to exploit
05Prerequisites
Admin must be logged into WordPress and visit an attacker-controlled webpage.
Key dates
06Disclosure timeline
May 16, 2025
CVE published
April 28, 2026
Record updated