The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 20240502. This allows unauthenticated attackers to execute arbitrary shortcodes. The severity and exploitability depends on the functionality of other plugins installed in the environment.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 |
Thu, 26 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:wpkube:simple_basic_contact_form:-:*:*:*:*:wordpress:*:* | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:28:25.041Z
Reserved: 2024-04-24T20:00:16.133Z
Link: CVE-2024-4144
Updated: 2024-08-01T20:33:52.480Z
Status : Deferred
Published: 2024-05-14T16:17:33.483
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-4144
No data.