PT-2026-79589 · WordPress · Ws Form Lite

·

CVE-2026-4703

·

Published

2026-08-22

·

Updated

2026-08-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WS Form LITE – Drag & Drop Contact Form Builder versions prior to 1.10.81
Description The plugin is susceptible to PHP Object Injection, a condition where untrusted input is deserialized, allowing an attacker to inject PHP objects. This occurs through the processing of form submission meta values. While the software itself does not contain a known POP chain (Property-Oriented Programming, a technique used to execute arbitrary code by leveraging existing classes in the application), the issue becomes critical if another installed plugin or theme provides one. In such cases, an unauthenticated attacker could potentially delete arbitrary files, retrieve sensitive data, or execute code.
Recommendations Update the plugin to a version newer than 1.10.80.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4703

Affected Products

Ws Form Lite