Skip to content
EXPLOIT
.CC
CVEs
Search
About
synced 2 HR AGO
T-2H
01
Record
STATE: —
02
Description
SRC: CNA
03
Metadata
SCHEMA: CVE JSON 5
04
Affected products
PAIRS: —
05
References
REFS: —
01
Record
STATE: PUBLISHED
CVE-2026-4703
WS Form LITE <= 1.10.80 - Unauthenticated PHP Object Injection via Form Submission
Critical
PUBLISHED
CNA: Wordfence
Base score
9.8
CVSS v3.x
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
View raw JSON
CVE Program record
02
Description
CNA: Wordfence
WS Form LITE <= 1.10.80 - Unauthenticated PHP Object Injection via Form Submission
03
Metadata
SCHEMA: 5.2
Published
2026-08-22 15:27Z
2 HR AGO
Last updated
2026-08-22 15:27Z
2 HR AGO
Reserved
2026-03-23
Assigning CNA
Wordfence
Record state
PUBLISHED
Severity
Critical (CVSS 9.8)
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-502
Deserialization of Untrusted Data
Base
SSVC decision
No CISA-ADP assessment
Data version
5.2
Document digest
ac81f8ff0e3256451453727279d960d5f2dc4cabaade5ed2f61542af6d219797
04
Affected products
PAIRS: 1
Vendor
Product
Versions
Platforms
westguard
WS Form LITE – Drag & Drop Contact Form Builder
0 to 1.10.80
—
05
References
REFS: 4
www.wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/df36eae9-6f2b-432c-a765-57450939b344?source=cve
plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/ws-form/trunk/includes/core/class-ws-form-submit.php#L1061
plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/ws-form/trunk/includes/class-ws-form-common.php#L7154
plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3489609/