Views for WPForms – Display & Edit WPForms Entries on your site frontend Security & Risk Analysis

wordpress.org/plugins/views-for-wpforms-lite

Display and Edit WPForms Entries Directly on Your Website with No Coding Knowledge Needed.

1K active installs v3.4.6 PHP 5.6+ WP 5.0+ Updated Mar 11, 2026
databasedisplay-entriestablewpforms
99
A · Safe
CVEs total5
Unpatched0
Last CVEJan 24, 2024
Safety Verdict

Is Views for WPForms – Display & Edit WPForms Entries on your site frontend Safe to Use in 2026?

Generally Safe

Score 99/100

Views for WPForms – Display & Edit WPForms Entries on your site frontend has a strong security track record. Known vulnerabilities have been patched promptly.

5 known CVEsLast CVE: Jan 24, 2024Updated 23d ago
Risk Assessment

The plugin "views-for-wpforms-lite" v3.4.6 exhibits a mixed security posture. On the positive side, the static analysis shows no dangerous functions, all SQL queries use prepared statements, and there are no external HTTP requests or file operations, which are good indicators of secure coding practices. Additionally, the plugin implements nonce and capability checks on most of its entry points. However, concerns arise from the vulnerability history, which shows a significant number of past medium-severity CVEs, primarily related to Missing Authorization and Improper Access Control. This pattern suggests a recurring weakness in how the plugin handles user permissions.

The static analysis did reveal some areas for improvement. While the total attack surface appears protected, the presence of 2 flows with unsanitized paths in the taint analysis is a concern, even though they are not currently classified as critical or high severity. Furthermore, the relatively low percentage of properly escaped output (52%) indicates potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not consistently and correctly sanitized before being displayed. Despite the absence of currently unpatched vulnerabilities, the historical trend of authorization-related issues warrants careful monitoring and continued security scrutiny.

Key Concerns

  • 5 medium severity CVEs in history
  • Only 52% of output properly escaped
  • 2 flows with unsanitized paths
Vulnerabilities
5

Views for WPForms – Display & Edit WPForms Entries on your site frontend Security Vulnerabilities

CVEs by Year

5 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
5

5 total CVEs

CVE-2024-0372medium · 4.3Missing Authorization

Views for WPForms <= 3.2.2 - Missing Authorization via get_form_fields

Jan 24, 2024 Patched in 3.2.3 (188d)
CVE-2024-0374medium · 4.3Improper Access Control

Views for WPForms <= 3.2.2 - Cross-Site Request Forgery via create_view

Jan 24, 2024 Patched in 3.2.3 (188d)
CVE-2024-0370medium · 4.3Improper Access Control

Views for WPForms <= 3.2.2 - Missing Authorization via save_view

Jan 24, 2024 Patched in 3.2.3 (188d)
CVE-2024-0371medium · 4.3Improper Access Control

Views for WPForms <= 3.2.2 - Missing Authorization via create_view

Jan 24, 2024 Patched in 3.2.3 (188d)
CVE-2024-0373medium · 4.3Improper Access Control

Views for WPForms <= 3.2.2 - Cross-Site Request Forgery via save_view

Jan 24, 2024 Patched in 3.2.3 (188d)
Code Analysis
Analyzed Mar 16, 2026

Views for WPForms – Display & Edit WPForms Entries on your site frontend Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
20
22 escaped
Nonce Checks
3
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

52% escaped42 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
views_editor (inc\admin\class-wpforms-views-editor.php:13)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Views for WPForms – Display & Edit WPForms Entries on your site frontend Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 4

authwp_ajax_views_get_form_fieldsinc\admin\class-wpforms-views-ajax.php:6
authwp_ajax_wpforms_views_get_form_fieldsinc\admin\class-wpforms-views-ajax.php:7
authwp_ajax_wpf_views_create_viewinc\admin\class-wpforms-views-ajax.php:10
authwp_ajax_wpforms_save_viewinc\admin\class-wpforms-views-ajax.php:12

Shortcodes 1

[wpforms-views] inc\class-wpforms-views-shortcode.php:12
WordPress Hooks 29
actionadmin_menuinc\admin\class-wpforms-views-editor.php:6
actionadmin_menuinc\admin\class-wpforms-views-list-table.php:6
filterviews_edit-wpforms-viewsinc\admin\class-wpforms-views-list-table.php:7
filterget_edit_post_linkinc\admin\class-wpforms-views-list-table.php:8
filterpost_row_actionsinc\admin\class-wpforms-views-list-table.php:9
actionadmin_menuinc\admin\class-wpforms-views-lite-support.php:5
filterwpforms_admin_headerinc\admin\class-wpforms-views-lite-support.php:7
filterwpforms_admin_flyoutmenuinc\admin\class-wpforms-views-lite-support.php:8
actioninitinc\admin\class-wpforms-views-posttype.php:6
filtermanage_wpforms-views_posts_columnsinc\admin\class-wpforms-views-posttype.php:7
actionmanage_wpforms-views_posts_custom_columninc\admin\class-wpforms-views-posttype.php:8
actionadmin_menuinc\admin\class-wpforms-views-services.php:5
filterwpforms_admin_headerinc\admin\class-wpforms-views-services.php:7
filterwpforms_admin_flyoutmenuinc\admin\class-wpforms-views-services.php:8
actionadmin_menuinc\admin\class-wpforms-views-upgrade-to-pro-page.php:5
filterwpforms_admin_headerinc\admin\class-wpforms-views-upgrade-to-pro-page.php:7
filterwpforms_admin_flyoutmenuinc\admin\class-wpforms-views-upgrade-to-pro-page.php:8
actioninitinc\admin\review\class-wpforms-views-review.php:14
actionadmin_noticesinc\admin\review\class-wpforms-views-review.php:24
actionnetwork_admin_noticesinc\admin\review\class-wpforms-views-review.php:25
actionuser_admin_noticesinc\admin\review\class-wpforms-views-review.php:26
actionelementor/widgets/registerinc\elementor\class-wpforms-views-elemntor-widget-init.php:14
actioninitviews-block\class-wpforms-views-block.php:5
actioninitviews-block\class-wpforms-views-block.php:6
actionadmin_enqueue_scriptsviews-block\class-wpforms-views-block.php:7
actionadmin_noticeswpforms-views.php:21
actionplugins_loadedwpforms-views.php:53
actionadmin_enqueue_scriptswpforms-views.php:79
actionwp_enqueue_scriptswpforms-views.php:81
Maintenance & Trust

Views for WPForms – Display & Edit WPForms Entries on your site frontend Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version5.6
Downloads90K

Community Trust

Rating100/100
Number of ratings24
Active installs1K
Developer Profile

Views for WPForms – Display & Edit WPForms Entries on your site frontend Developer Profile

Aman

11 plugins · 8K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
138 days
View full developer profile
Detection Fingerprints

How We Detect Views for WPForms – Display & Edit WPForms Entries on your site frontend

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/views-for-wpforms-lite/assets/css/sweetalert2.min.css/wp-content/plugins/views-for-wpforms-lite/assets/js/sweetalert2.min.js/wp-content/plugins/views-for-wpforms-lite/assets/css/admin.css/wp-content/plugins/views-for-wpforms-lite/assets/js/admin.js/wp-content/plugins/views-for-wpforms-lite/assets/css/font-awesome.css/wp-content/plugins/views-for-wpforms-lite/assets/css/pure-min.css/wp-content/plugins/views-for-wpforms-lite/assets/css/grids-responsive-min.css/wp-content/plugins/views-for-wpforms-lite/assets/css/wpforms-views-editor.css+5 more
Script Paths
/wp-content/plugins/views-for-wpforms-lite/assets/js/sweetalert2.min.js/wp-content/plugins/views-for-wpforms-lite/assets/js/admin.js/wp-content/plugins/views-for-wpforms-lite/build/static/js/main.js/wp-content/plugins/views-for-wpforms-lite/build/static/js/vendors~main.js/wp-content/plugins/views-for-wpforms-lite/assets/js/post-editor.js
Version Parameters
/wp-content/plugins/views-for-wpforms-lite/assets/css/wpforms-views-display.css?ver=/wp-content/plugins/views-for-wpforms-lite/build/static/css/main.css?ver=/wp-content/plugins/views-for-wpforms-lite/assets/js/admin.js?ver=/wp-content/plugins/views-for-wpforms-lite/assets/js/sweetalert2.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpforms-views-editor-wrapwpforms-views-editor-fieldwpforms-views-editor-field-inputwpf-views-admin-noticewpforms-views-wrap
Data Attributes
data-block
JS Globals
wpf_views_adminwp_views_block
REST Endpoints
/wp-json/wpforms-views/v1/settings
Shortcode Output
[wpforms-views id=
FAQ

Frequently Asked Questions about Views for WPForms – Display & Edit WPForms Entries on your site frontend