WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Lead Form Builder & Contact Form

Drag & Drop Contact Form Builder for WordPress to create contact, lead generation, Cloudflare Turnstile CAPTCHA Support.

11Reported vulnerabilities
7.2Highest CVSS score
2.2.5Latest version
9,000+Active installs

What to do now

Update Lead Form Builder & Contact Form to 2.0.2 or later. 11 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 7, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2021-24967 Medium 6.1 1.2% Before 1.6.4 1.6.4 December 27, 2021
CVE-2024-3637 Medium 6.1 0.5% 1.8.9 and earlier 1.9.8 May 3, 2024
CVE-2024-10475 Medium 4.8 0.3% Before 1.9.8 1.9.8 May 15, 2025
CVE-2022-23179 Medium 4.8 0.5% Before 1.7.0 1.7.0 January 16, 2024
CVE-2022-23180 Medium 4.3 0.5% Before 1.7.4 1.7.4 January 16, 2024
CVE-2026-32532 High 7.2 0.1% 2.0.1 and earlier 2.0.2 March 23, 2026
CVE-2026-1454 High 7.2 0.2% 0 to 2.0.1 (inclusive) 2.0.2 March 11, 2026
CVE-2024-4261 Medium 5.4 0.3% 0 to 1.9.1 (inclusive) 1.9.2 May 22, 2024
CVE-2025-68046 Medium 4.3 0.4% 2.0.1 and earlier 2.0.2 January 20, 2026
CVE-2024-1416 Medium 4.3 0.3% 0 to 1.8.9 (inclusive) 1.9.0 May 2, 2024
CVE-2024-1415 Medium 4.3 0.3% 0 to 1.8.9 (inclusive)
- to 1.8.9 (inclusive)
1.9.0 May 2, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.