CVE-2024-6770

Published
View on NVD ↗
CVSS v3
7.2
HIGH
CVSS v2
N/A
Affected
1
PROJECT

Description

The Lifetime free Drag & Drop Contact Form Builder for WordPress VForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p><a href="https://vpsuform.info/" rel="nofollow ugc">VPSUForm</a> is a powerful, fast, and conversion-focused Contact Form Builder &amp; Email Automation platform for WordPress. Built for small businesses, agencies, bloggers, course creators, and eCommerce sites, VPSUForm helps you capture leads, automate follow-ups, and turn visitors into customers — without coding.</p> <p>VPSUForm is more than a contact form plugin. It’s a complete lead-capture and engagement toolkit: drag-and-drop form building, flexible conditional logic, robust spam protection, and a built-in Email Automation system that sends targeted autoresponders and follow-ups based on user actions. If you want forms that convert, deliver leads to your team, and automate the follow-up process — VPSUForm is the fast, lightweight solution.</p> <h3>Create your VPSUForm in a minute</h3> <p><span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/q4EncfhCBac?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span></p> <h3>Why VPSUForm?</h3> <p>Focus on conversions &amp; automation — VPSUForm is designed to help you capture more leads and reduce manual email follow-ups by automating the entire response flow. Use it for lead magnets, onboarding sequences, support tickets, booking requests, and more.</p> <p>Beginner-friendly — A clean drag-and-drop interface that makes form creation fast and intuitive. No coding required.</p> <p>Lightweight &amp; fast — Optimized for performance so forms load quickly and don’t slow your site.</p> <p>Flexible &amp; extendable — Integrations, webhooks, SMTP, and export tools to connect VPSUForm to your workflow.</p> <h3>Key Features</h3> <ul> <li>Email Automation &amp; Autoresponders — Send automated, personalized emails after submissions. Support multiple templates and sequences per form.</li> <li>Drag &amp; Drop Form Builder — Build complex forms visually in minutes.</li> <li>Conditional Logic — Show/hide fields, change email actions, and trigger automations based on user answers.</li> <li>Multiple Email Notifications — Send different emails to admins, users, or third-parties.</li> <li>Mobile Responsive — All forms are fully responsive and look great on every device.</li> <li>Entries Manager &amp; Export — View, search, filter, and export submissions to CSV.</li> <li>Integrations — Google Sheets, Zapier, Webhooks, SMTP support for reliable inbox delivery.</li> <li>Spam Protection — Google reCAPTCHA and hCaptcha support.</li> <li>File Uploads &amp; Media Fields — Accept resumes, images, attachments and more.</li> <li>Page Breaks &amp; Multi-Step Forms — Create multi-page forms for higher conversions.</li> <li>Custom Confirmation Options — Show message, redirect to page, or send users to a custom URL upon submission.</li> <li>Developer Friendly — Hooks, shortcodes, and easy templating for customization.</li> <li>Send Attachments With Emails</li> </ul> <h3>📌 All the Fields You’ll Ever Need</h3> <p><strong>Basic Fields: </strong><br /> * Title<br /> * Single Line Text<br /> * Paragraph Text<br /> * Dropdown Field</p> <p><strong>Choice Fields: </strong><br /> * Multiple Choice (Radio Buttons)<br /> * Checkboxes<br /> * Range Slider<br /> * Net Promoter Score<br /> * Rating</p> <p><strong>Contact Fields: </strong><br /> * Name (First Name, Middle Name, Last Name)<br /> * Email Address<br /> * Phone<br /> * Phone with Country Code<br /> * Website/URL<br /> * Address</p> <p><strong>Advanced Fields: </strong><br /> * Password<br /> * Date/Time<br /> * Date<br /> * Time<br /> * Months<br /> * Weeks<br /> * Color Picker<br /> * Geolocation<br /> * E-Signature<br /> * Hidden Field</p> <p><strong>Media &amp; Extras: </strong><br /> * File Upload<br /> * Image<br /> * Link<br /> * Terms &amp; Conditions<br /> * Page Break<br /> * Divider<br /> * Button</p> <p><strong>Anti-Spam: </strong><br /> * reCAPTCHA<br /> * hCaptcha</p> <h3>Reusable Form Templates</h3> <p>Why waste time building the same form again and again? VPSUForm comes with pre-made form templates that you can launch with one click — just customize the fields you want and publish instantly. Build forms in minutes, not hours.</p> <p>Some ready-to-use form types included:</p> <ul> <li>Simple Contact Form</li> <li>Auction Item Registration Form</li> <li>Online Event Registration Form</li> <li>Inline Newsletter Signup Form</li> <li>Subscribe / Lead Capture Form</li> <li>File Upload &amp; Attachment Form</li> </ul> <h3>Who Should Use VPSUForm?</h3> <p><strong>VPSUForm is perfect for:</strong></p> <ul> <li>Small businesses and local services capturing leads and appointments</li> <li>Bloggers and content creators collecting feedback and subscribers</li> <li>Agencies building client forms and lead funnels</li> <li>eCommerce stores capturing pre-orders, returns, and contact requests</li> <li>Course creators and LMS sites for signups and onboarding</li> <li>Non-profits and event organizers for registrations and volunteer signups</li> </ul> <p><strong>Real Use Cases</strong></p> <ul> <li>Lead magnet opt-ins with automated email delivery</li> <li>Appointment booking and confirmation sequences</li> <li>Job applications with file uploads and HR notifications</li> <li>Support ticket forms with automated acknowledgement emails</li> <li>Survey &amp; feedback forms with conditional follow-ups</li> <li>Event registration with custom confirmation pages</li> </ul> <p><strong>Integrations &amp; Export</strong></p> <ul> <li>Google Sheets — Auto-save submissions to sheets</li> <li>Zapier &amp; Webhooks — Connect to thousands of apps</li> <li>SMTP — Use a trusted SMTP provider to improve deliverability</li> <li>CSV Export — Download entries for reporting or CRM import</li> </ul> <p><strong>Security &amp; Privacy</strong></p> <p>VPSUForm includes spam protection (reCAPTCHA &amp; hCaptcha) and follows best practices for secure form handling. Entries can be exported and stored as needed, and file uploads are handled via WordPress media or server upload settings. Always follow local privacy laws (GDPR, CCPA) when collecting personal data.</p> <p><strong>Benefits at a Glance</strong></p> <ul> <li>Faster form creation — Build forms in minutes with drag-and-drop.</li> <li>Higher conversions — Multi-step forms, conditional logic, and conversion-focused features.</li> <li>Less manual work — Automated email flows and notifications.</li> <li>Better lead management — Store, export, and integrate submissions with your tools.</li> <li>No developer required — Intuitive UI for non-technical users.</li> </ul> <h3>Support &amp; Documentation</h3> <p>Need help or want tutorials? Visit our documentation and support pages:</p> <p>👉 <a href="https://vpsuform.info/" rel="nofollow ugc">Official Website</a></p> <p>👉 <a href="https://vpsuform.info/contact-us/" rel="nofollow ugc">Support</a></p> <p>👉 <a href="https://www.youtube.com/channel/UCVYd-Hh6pu-eQcP5vzD2x5g" rel="nofollow ugc">YouTube Tutorials</a></p>
WordPress Plugin DirectoryWordPress Plugin Directory
22.8K