The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to Local File Inclusion. Authenticated attackers with Administrator-level access can include and execute arbitrary .php files on the server, allowing PHP code execution. This vulnerability has a CVSS score of 6.6 and is classified as MEDIUM severity. The vulnera [truncated]
CVE-2026-49768 is a critical vulnerability in the Happyforms plugin for WordPress, affecting versions up to and including 1.26.13. This vulnerability allows for unauthenticated PHP object injection, which can lead to severe consequences, including code execution, data breaches, and complete control of the affected system. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 9.8, [truncated]