
Lead Form Builder & Contact Form Security & Risk Analysis
wordpress.org/plugins/lead-form-builderFast Drag & Drop Contact From Builder and Lead Generation Tool With Google One Tap Login. Supports Block Editor.
Is Lead Form Builder & Contact Form Safe to Use in 2026?
Generally Safe
Score 89/100Lead Form Builder & Contact Form has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "lead-form-builder" v2.1.0 exhibits a mixed security posture. While it demonstrates good practices in SQL query preparation (88%) and output escaping (87%), and implements a reasonable number of nonce and capability checks, there are significant areas of concern. The presence of two unprotected AJAX handlers creates an immediate attack vector for unauthorized actions. The taint analysis reveals a high number of flows with unsanitized paths (13 out of 21 analyzed), including nine with high severity, suggesting potential for serious vulnerabilities like code injection or cross-site scripting if these flows are triggered by user input. The use of the `unserialize` function, flagged as a dangerous function, is another red flag, as it can lead to remote code execution if not handled with extreme caution and proper input validation.
The plugin's vulnerability history is a major concern, with ten known CVEs, including two high-severity vulnerabilities. While none are currently unpatched in this specific version, the recurring types of vulnerabilities (Exposure of Sensitive Information, Code Injection, CSRF, Missing Authorization, XSS) indicate a pattern of security weaknesses that have historically been exploited. The fact that the last vulnerability was dated in the future (2026-03-10) is likely an anomaly in the data provided and should be disregarded in a real-world assessment. Overall, while the plugin has some strengths in secure coding practices, the combination of unprotected entry points, critical taint flows, dangerous function usage, and a history of diverse, high-severity vulnerabilities points to a moderately high risk that requires careful attention and remediation.
Key Concerns
- Unprotected AJAX handlers
- High number of unsanitized taint flows (High severity)
- Use of dangerous function: unserialize
- Known CVEs: 2 High severity
- Known CVEs: 8 Medium severity
- Vulnerability types: Code Injection, CSRF, Missing Auth, XSS
Lead Form Builder & Contact Form Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
Responsive Contact Form Builder & Lead Generation Plugin <= 2.0.1 - Unauthenticated Stored Cross-Site Scripting
Contact Form & Lead Form Elementor Builder <= 2.0.1 - Authenticated (Subscriber+) Information Exposure
Responsive Contact Form Builder & Lead Generation Plugin <= 1.9.7 - Authenticated (Admin+) Stored Cross-Site Scripting
Responsive Contact Form Builder & Lead Generation Plugin <= 1.9.1 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
Responsive Contact Form Builder & Lead Generation Plugin <= 1.9.7 - Authenticated (Admin+) Stored Cross-Site Scripting
Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Missing Authorization
Responsive Contact Form Builder & Lead Generation Plugin <= 1.8.9 - Cross-Site Request Forgery
Contact Form & Lead Form Elementor Builder < 1.7.4 - Arbitrary Settings Change
Responsive Contact Form Builder & Lead Generation Plugin < 1.7.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Contact Form & Lead Form Elementor Builder <= 1.6.3 - Unauthenticated Stored Cross-Site Scripting
Lead Form Builder & Contact Form Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Lead Form Builder & Contact Form Attack Surface
AJAX Handlers 22
Shortcodes 1
WordPress Hooks 22
Maintenance & Trust
Lead Form Builder & Contact Form Maintenance & Trust
Maintenance Signals
Community Trust
Lead Form Builder & Contact Form Alternatives
Mailster Add-On for FormCraft
formcraft-mymail
Create gorgeous optin forms for your site with FormCraft, and grow your Mailster list.
MailPoet Add-On for FormCraft
mailpoet-for-formcraft
Create gorgeous optin forms for your site with FormCraft, and grow your MailPoet list.
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
metform
The most popular Elementor forms builder to create WordPress forms like contact forms, booking forms, feedback form, survey forms, application forms a …
RTMForm Builder
romethemeform
RTMForm For Elementor Plugin is an Form Builder for Elementor, and Widget Ready to use.
Smart Grid-Layout Design for Contact Form 7
cf7-grid-layout
This plugins allow pure CSS responsive grid layouts for contact form 7. It enables rich interlinking of your CMS data via taxonomy/posts populated dr …
Lead Form Builder & Contact Form Developer Profile
48 plugins · 66K total installs
How We Detect Lead Form Builder & Contact Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lead-form-builder/css/lfb-styler.css/wp-content/plugins/lead-form-builder/block/app.js/wp-content/plugins/lead-form-builder/inc/lf-db.js/wp-content/plugins/lead-form-builder/inc/inc.js/wp-content/plugins/lead-form-builder/notify/notify.js/wp-content/plugins/lead-form-builder/notify/notify.css/wp-content/plugins/lead-form-builder/block/app.js/wp-content/plugins/lead-form-builder/inc/lf-db.js/wp-content/plugins/lead-form-builder/inc/inc.js/wp-content/plugins/lead-form-builder/notify/notify.jslead-form-builder/css/lfb-styler.css?ver=lead-form-builder/block/app.js?ver=lead-form-builder/inc/lf-db.js?ver=lead-form-builder/inc/inc.js?ver=lead-form-builder/notify/notify.js?ver=lead-form-builder/notify/notify.css?ver=HTML / DOM Fingerprints
lfb-form-containerlfb-input-fieldlfb-submit-buttonlfb-styler-widget<!--Lead Form Builder Start--><!--Lead Form Builder End--><!-- Elementor Lead Form Styler Widget -->data-lfb-form-iddata-lfb-form-settingswindow.LFB_Ajaxvar leadFormBuilderAdmin;/wp-json/lead-form-builder/v1/submit/wp-json/lead-form-builder/v1/get-form[lead_form_builder id='']