Wise Agent Lead Forms Security & Risk Analysis

wordpress.org/plugins/wiseagentleadform

Short Description: The Wise Agent WordPress plugin lets you easily add capture forms to any page on your WordPress site.

100 active installs v3.3.2 PHP + WP 5.2+ Updated Mar 4, 2026
capture-leadscrmlead-capture-formsreal-estate-toolswise-agent
100
A · Safe
CVEs total1
Unpatched0
Last CVESep 9, 2021
Safety Verdict

Is Wise Agent Lead Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Wise Agent Lead Forms has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 9, 2021Updated 1mo ago
Risk Assessment

The 'wiseagentleadform' plugin v3.3.2 exhibits a generally positive security posture with several strong practices. The absence of critical and high-severity vulnerabilities in its history, along with all known CVEs being patched, is reassuring. The code analysis shows a commitment to secure coding, with 100% of SQL queries using prepared statements and a significant 85% of outputs being properly escaped. The presence of nonce and capability checks on entry points further bolsters its defense.

However, there are a few areas that warrant attention. The existence of one flow with an unsanitized path in the taint analysis, even if not classified as critical or high, suggests a potential for improper input handling. While the overall attack surface is small and appears to be protected by authentication checks, the single shortcode could theoretically be a vector if not handled with extreme care. The plugin also makes external HTTP requests, which can introduce risks if the remote endpoints are compromised or if the plugin doesn't validate the responses adequately.

In conclusion, 'wiseagentleadform' v3.3.2 is a relatively secure plugin, demonstrating good coding practices and a clear history of addressing vulnerabilities. The main concerns lie in the single identified unsanitized path and the potential risks associated with external HTTP requests, although these do not appear to be exploited in its known vulnerability history. Continuous monitoring for new vulnerabilities and careful handling of its external dependencies would be prudent.

Key Concerns

  • Flow with unsanitized path
  • External HTTP requests present
Vulnerabilities
1

Wise Agent Lead Forms Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2021-38335medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Wise Agent Capture Forms <= 2.0 - Reflected Cross-Site Scripting

Sep 9, 2021 Patched in 3.0 (866d)
Code Analysis
Analyzed Mar 16, 2026

Wise Agent Lead Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
91 escaped
Nonce Checks
3
Capability Checks
10
File Operations
0
External Requests
7
Bundled Libraries
0

Output Escaping

85% escaped107 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

5 flows1 with unsanitized paths
wiseagent_register_cors (wiseagent.php:273)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Wise Agent Lead Forms Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_wa_capture_formwiseagent.php:583
noprivwp_ajax_wa_capture_formwiseagent.php:584

Shortcodes 1

[wiseagent] wiseagent.php:581
WordPress Hooks 23
actionadmin_menuwiseagent.php:23
actionadmin_post_wa_oauth2wiseagent.php:25
actionadmin_post_wa_oauth2_disconnectwiseagent.php:26
actionadmin_post_wa_refresh_capture_formswiseagent.php:27
actionadmin_enqueue_scriptswiseagent.php:29
actionadmin_initwiseagent.php:31
actioninitwiseagent.php:32
actionwp_enqueue_scriptswiseagent.php:37
actionadmin_enqueue_scriptswiseagent.php:38
actionwp_enqueue_scriptswiseagent.php:40
actionadmin_noticeswiseagent.php:43
actionrest_api_initwiseagent.php:46
filterrest_pre_serve_requestwiseagent.php:274
actionelementor/widgets/registerwiseagent.php:585
actiontemplate_redirectwiseagent.php:591
actionadd_meta_boxeswiseagent.php:594
actionsave_post_testimonialwiseagent.php:597
actionsave_post_eventwiseagent.php:598
actionadmin_initwiseagent.php:601
actionedit_form_after_titlewiseagent.php:604
actionpre_get_postswiseagent.php:607
filterelementor/query/get_query_args/post_type=eventwiseagent.php:610
actionupdate_option_wiseagent_content_optionswiseagent.php:1314
Maintenance & Trust

Wise Agent Lead Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Wise Agent Lead Forms Developer Profile

wiseagentwp

1 plugin · 100 total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
866 days
View full developer profile
Detection Fingerprints

How We Detect Wise Agent Lead Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wiseagentleadform/css/wa_capture_form.css/wp-content/plugins/wiseagentleadform/js/wa_capture_form.js
Script Paths
/wp-content/plugins/wiseagentleadform/captureForm.js
Version Parameters
wiseagentleadform/captureForm.js?ver=1.0.2

HTML / DOM Fingerprints

Data Attributes
data-form-id
JS Globals
wa_capture_form_settings
Shortcode Output
[wiseagent_capture_form]
FAQ

Frequently Asked Questions about Wise Agent Lead Forms