What the vulnerability does
01Description
Insertion of Sensitive Information Into Sent Data vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Retrieve Embedded Sensitive Data.This issue affects Contact Form by WPForms: from n/a through <= 1.9.8.7.
Explanation of Vulnerability in Simple Terms
02Summary
Contact Form by WPForms versions up to 1.9.8.7 expose sensitive information to unauthenticated users who visit a specially crafted page. An attacker can read confidential data without needing to log in, but the victim must interact with the malicious link. Update to a version newer than 1.9.8.7 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read sensitive information from the site without logging in.
Potential impact on your site
04Site Impact
Confidential data (form submissions, user details, or plugin settings) may be exposed to anyone who visits a crafted URL.
Conditions required to exploit
05Prerequisites
Victim must click a malicious link or visit an attacker-controlled page.
Key dates
06Disclosure timeline
March 25, 2026
CVE published
April 29, 2026
Record updated