[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feQGTKW8_tMU_8RP_507fmw01pUpfkQLfqh-B956WZCg":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":18,"download_link":25,"security_score":26,"vuln_count":27,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30,"vulnerabilities":31,"developer":115,"crawl_stats":37,"alternatives":119,"analysis":214,"fingerprints":954},"zoho-crm-forms","Zoho CRM Lead Magnet","1.8.1.9","zohocrm","https:\u002F\u002Fprofiles.wordpress.org\u002Fzohocrm\u002F","\u003Cp>Websites are one of the most important sources of leads for your business. That means your CRM system should be well integrated with your website to contextually capture each and every visitor to turn them into a lead.\u003C\u002Fp>\n\u003Cp>Introducing the Zoho CRM Lead Magnet plugin for WordPress. This lets you create webforms, embed them in your website, and automatically capture leads directly into your CRM with zero attenuation.\u003C\u002Fp>\n\u003Cp>Not only is the integration easy to set-up but it’s also easy on your wallet.\u003C\u002Fp>\n\u003Ch3>Overall usage flow\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Install the Zoho CRM forms plugin from the WordPress plugin Marketplace.\u003C\u002Fli>\n\u003Cli>Create a form using Zoho CRM webforms or Contact form 7 plugin.\u003C\u002Fli>\n\u003Cli>Configure the settings for your form.\u003C\u002Fli>\n\u003Cli>Use the short code to embed the form.\u003C\u002Fli>\n\u003Cli>A prospect’s information is automatically captured upon entering your site. All that’s left is lead nurturing.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>For businesses that want to maximize their websites, the Zoho CRM Lead Capture plugin for WordPress CMS is an ideal solution.\u003C\u002Fp>\n\u003Ch3>Key features\u003C\u002Fh3>\n\u003Cp>Two forms, one solution\u003C\u002Fp>\n\u003Cp>This plugin works well with forms created using Zoho CRM and Contact 7 Form plugin.\u003C\u002Fp>\n\u003Cp>Light on code\u003C\u002Fp>\n\u003Cp>Creating a form is incredibly simple and the entire process of establishing an integration involves a few drag-drops and copy-pastes. Simply create, embed, and capture.\u003C\u002Fp>\n\u003Cp>Capture leads and more\u003C\u002Fp>\n\u003Cp>Using this plugin not only lets you capture leads but also additional custom modules you create for unique business needs.\u003C\u002Fp>\n\u003Cp>Capture. nurture. win.\u003C\u002Fp>\n\u003Cp>The Information entered in a website’s form is automatically pushed into Zoho CRM with zero attenuation. Now you never miss out on another lead.\u003C\u002Fp>\n\u003Cp>Light on your purse\u003C\u002Fp>\n\u003Cp>The plugin is absolutely free of cost. No hidden fees, no additional costs. All you need is a website hosted with WordPress and a Zoho CRM account.\u003C\u002Fp>\n\u003Cp>Special mail-tags support\u003C\u002Fp>\n\u003Col>\n\u003Cli>[_url]\u003C\u002Fli>\n\u003Cli>[_site_title]\u003C\u002Fli>\n\u003Cli>[_site_description]\u003C\u002Fli>\n\u003Cli>[_site_url]\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>For examples\u003Cbr \u002F>\n[hidden get-url default:_url]\u003Cbr \u002F>\n[hidden site_title default:_site_title]\u003Cbr \u002F>\n[hidden site-description default:_site_description]\u003Cbr \u002F>\n[hidden site-url default:_site_url]\u003C\u002Fp>\n\u003Cp>Please feel free to contact us for any further assistance: \u003Cstrong>support@zohoextensions.com\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>A vulnerability reporting program in “Bug Bounty”, to reach the community of researchers, is in place, which recognizes and rewards the work of security researchers. We are committed to working with the community to verify, reproduce, respond and implement appropriate solutions for the reported vulnerabilities.\u003Cbr \u002F>\nIf you happen to find any, please submit the issues at https:\u002F\u002Fbugbounty.zohocorp.com\u002F. If you want to directly report vulnerabilities to us, mail us at \u003Cstrong>security@zohocorp.com\u003C\u002Fstrong>.\u003C\u002Fp>\n","Websites are one of the most important sources of leads for your business.",3000,219694,62,25,"2026-01-28T07:18:00.000Z","6.9.0","6.0","",[20,21,22,23,24],"contact-form-7","lead-capture","lead-magnet","web-to-lead","zoho-crm-wordpress","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fzoho-crm-forms.zip",67,6,1,"2026-01-15 00:00:00","2026-03-15T15:16:48.613Z",[32,46,61,76,91,104],{"id":33,"url_slug":34,"title":35,"description":36,"plugin_slug":4,"theme_slug":37,"affected_versions":38,"patched_in_version":37,"severity":39,"cvss_score":40,"cvss_vector":41,"vuln_type":42,"published_date":29,"updated_date":43,"references":44,"days_to_patch":37},"CVE-2026-24595","zoho-crm-lead-magnet-missing-authorization","Zoho CRM Lead Magnet \u003C= 1.8.1.7 - Missing Authorization","The Zoho CRM Lead Magnet plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.8.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.",null,"\u003C=1.8.1.7","medium",4.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:N\u002FI:L\u002FA:N","Missing Authorization","2026-01-27 19:24:24",[45],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F745bd805-7b18-4633-ad5f-94d3a00e0807?source=api-prod",{"id":47,"url_slug":48,"title":49,"description":50,"plugin_slug":4,"theme_slug":37,"affected_versions":51,"patched_in_version":52,"severity":39,"cvss_score":53,"cvss_vector":54,"vuln_type":55,"published_date":56,"updated_date":57,"references":58,"days_to_patch":60},"CVE-2024-49297","zoho-crm-lead-magnet-authenticated-contributor-sql-injection","Zoho CRM Lead Magnet \u003C= 1.7.9.7 - Authenticated (Contributor+) SQL Injection","The Zoho CRM Lead Magnet plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.7.9.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","\u003C=1.7.9.7","1.7.9.8",6.5,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N","Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","2024-10-15 00:00:00","2024-11-11 16:30:33",[59],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F14e9d0a2-a1cb-4d3e-b6df-fba01d476936?source=api-prod",28,{"id":62,"url_slug":63,"title":64,"description":65,"plugin_slug":4,"theme_slug":37,"affected_versions":66,"patched_in_version":67,"severity":39,"cvss_score":68,"cvss_vector":69,"vuln_type":70,"published_date":71,"updated_date":72,"references":73,"days_to_patch":75},"CVE-2024-38696","zoho-crm-lead-magnet-reflected-cross-site-scripting","Zoho CRM Lead Magnet \u003C= 1.7.8.8 - Reflected Cross-Site Scripting","The Zoho CRM Lead Magnet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.7.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","\u003C=1.7.8.8","1.7.8.9",6.1,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:C\u002FC:L\u002FI:L\u002FA:N","Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","2024-07-11 00:00:00","2024-07-17 13:37:59",[74],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fcc940d0c-446a-417b-95ac-b5f8a0586906?source=api-prod",7,{"id":77,"url_slug":78,"title":79,"description":80,"plugin_slug":4,"theme_slug":37,"affected_versions":81,"patched_in_version":82,"severity":83,"cvss_score":84,"cvss_vector":85,"vuln_type":42,"published_date":86,"updated_date":87,"references":88,"days_to_patch":90},"CVE-2022-41978","zoho-crm-lead-magnet-missing-authorization-to-authenticated-subscriber-arbitrary-options-update","Zoho CRM Lead Magnet  \u003C= 1.7.5.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update","The Zoho CRM Lead Magnet plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on one of its functions in versions up to, and including, 1.7.5.8. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to update arbitrary options that can used to enable user registration and create administrative user accounts.","\u003C=1.7.5.8","1.7.5.9","high",8.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:L\u002FI:H\u002FA:H","2022-10-27 00:00:00","2024-01-22 19:56:02",[89],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F57caddaa-c548-4f07-ab34-327df62951b5?source=api-prod",453,{"id":92,"url_slug":93,"title":94,"description":95,"plugin_slug":4,"theme_slug":37,"affected_versions":96,"patched_in_version":97,"severity":39,"cvss_score":98,"cvss_vector":99,"vuln_type":70,"published_date":100,"updated_date":87,"references":101,"days_to_patch":103},"CVE-2021-33849","zoho-crm-lead-magnet-cross-site-scripting","Zoho CRM Lead Magnet \u003C= 1.7.2.4 - Cross-Site Scripting","A Cross-Site Scripting (XSS) attack can cause arbitrary code (JavaScript) to run in a user&#8217;s browser while the browser is connected to a trusted website. The attack targets your application's users and not the application itself while using your application as the attack's vehicle. The XSS payload executes whenever the user changes the form values or deletes a created form in Zoho CRM Lead Magnet Version 1.7.2.4.","\u003C=1.7.2.4","1.7.2.9",6.4,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N","2021-09-01 00:00:00",[102],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F54a610c6-2615-4900-bf63-8ae93aeabb8e?source=api-prod",874,{"id":105,"url_slug":106,"title":107,"description":108,"plugin_slug":4,"theme_slug":37,"affected_versions":109,"patched_in_version":110,"severity":39,"cvss_score":68,"cvss_vector":69,"vuln_type":70,"published_date":111,"updated_date":87,"references":112,"days_to_patch":114},"CVE-2019-19306","zoho-crm-lead-magnet-reflected-cross-site-scripting-2","Zoho CRM Lead Magnet \u003C= 1.6.9.1 - Reflected Cross-Site Scripting","The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.","\u003C1.6.9.2","1.6.9.2","2019-10-15 00:00:00",[113],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fe9171908-5b6e-44f3-ab93-899932be527f?source=api-prod",1561,{"slug":7,"display_name":7,"profile_url":8,"plugin_count":28,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":116,"trust_score":117,"computed_at":118},585,56,"2026-04-03T23:32:33.038Z",[120,145,165,185,202],{"slug":121,"name":122,"version":123,"author":124,"author_profile":125,"description":126,"short_description":127,"active_installs":128,"downloaded":129,"rating":130,"num_ratings":131,"last_updated":132,"tested_up_to":133,"requires_at_least":134,"requires_php":18,"tags":135,"homepage":139,"download_link":140,"security_score":141,"vuln_count":142,"unpatched_count":143,"last_vuln_date":144,"fetched_at":30},"wp-leads-builder-any-crm","Lead Form Data Collection to CRM","3.2","Smackcoders Inc.,","https:\u002F\u002Fprofiles.wordpress.org\u002Fsmackcoders\u002F","\u003Cp>Empower your WordPress website with the Lead Form Data Collection to CRM plugin, your ultimate solution for capturing WordPress contact form data and effortlessly transferring it to your CRM as Leads or Contacts. This powerful lead form data collection to CRM tool simplifies the data collection process and seamlessly integrates it with your CRM system, eliminating the need for manual data entry and reducing potential errors.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fgreat-product-superb-support-2\u002F\" rel=\"ugc\">https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fgreat-product-superb-support-2\u002F\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Great product. Superb support! I have been using the product for 3 years. It always functions as hoped for, and if not, there is reliable support!\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fgreat-plugin-and-awesome-support-184\u002F\" rel=\"ugc\">https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fgreat-plugin-and-awesome-support-184\u002F\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Great plugin and awesome support. I had issues configuring the pro plugin initially. The customer support team was very prompt in solving my problem. The plugin itself is very, very useful to as I use suitecrm to manage my leads.It made my life so easy! Great work guys. Please keep it up!\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fthe-plugin-and-the-support-is-amazing\u002F\" rel=\"ugc\">https:\u002F\u002Fwordpress.org\u002Fsupport\u002Ftopic\u002Fthe-plugin-and-the-support-is-amazing\u002F\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>The plugin and the support is amazing. We have been searching for a plugin for a long time that can integrate wordpress with vTiger, but we have not found any that meet the criteria required by our clients, until this one. Besides having integration with a lot of CRMs, it works with ContactForm7 and WooCommerce, the support team of this plugin is absolutely brilliant. I came to them with a connection problem that was caused by our server. They were patient and solved the problem quickly. In a word, A + plugin and support.\u003C\u002Fp>\n\u003Cp>With the Lead Form Data Collection to CRM, you can:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Effortlessly Collect and Send Leads Data to CRM:\u003C\u002Fstrong> Capture leads data from your WordPress forms or Contact Form 7 plugin forms with ease and send it to your integrated CRM.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Seamless CRM Integration:\u003C\u002Fstrong> Integrate your WordPress with any CRMs like Salesforce, Zoho, Vtiger, SuiteCRM, FreshSales, and Joforce CRM for streamlined lead management.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Embed Forms Anywhere:\u003C\u002Fstrong> Create dynamic shortcodes to embed web forms in posts, pages, custom posts, sidebars, widgets, and popups.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Secure Every Submissions:\u003C\u002Fstrong> Safeguard your lead data with built-in Captcha protection, ensuring data integrity.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Assign Leads Entering Your CRM to Sales Reps:\u003C\u002Fstrong> Automatically assign every lead entering your CRM(submitted via forms) to your CRM sales reps or admin or other user to handle.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Use Built-in Lead Forms:\u003C\u002Fstrong> Utilize the built-in Leads form provided by the plugin for your Lead Capturing, modify essential form settings if needed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Set up Advanced Form Settings:\u003C\u002Fstrong> Prevent from duplicate form submissions entering as leads into CRM with advanced duplicate handling options, configure form submission success and failure error messages and more.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The plugin’s simple and intuitive interface makes the form customization effortless. You can create, edit, and update form fields with ease to match your lead capture needs. Automate lead assignments, ensuring every submission reaches the right CRM user for quick follow-ups. Prevent from duplicate entries, customize success and error messages, fine-tune your form submissions and on.\u003C\u002Fp>\n\u003Ch4>Helpful links to try\u003C\u002Fh4>\n\u003Cp>Get the \u003Ca href=\"https:\u002F\u002Ftrial.smackcoders.com\u002Fwp-leads-builder-for-any-crm\u002F?utm_source=wordpress_org&utm_medium=readme&utm_campaign=lead_builder_free\" rel=\"nofollow ugc\">Free Private Trial of WP Leads Builder for CRM Pro\u003C\u002Fa>. See the plugin in action at our \u003Ca href=\"https:\u002F\u002Fdemo.smackcoders.com\u002Fwordpress\u002Fwp-admin\u002Fadmin.php?page=wp-leads-builder-any-crm-pro&utm_source=wordpress_org&utm_medium=readme&utm_campaign=lead_builder_free\" rel=\"nofollow ugc\">demo\u003C\u002Fa> instance.\u003C\u002Fp>\n\u003Cp>Visit our \u003Ca href=\"https:\u002F\u002Fwww.smackcoders.com\u002Fdocumentation\u002Fwordpress-leads-builder-for-any-crm-pro\u002Fcommunity-version?utm_source=wordpress_org&utm_medium=readme&utm_campaign=lead_builder_free\" rel=\"nofollow ugc\">Help Documentation\u003C\u002Fa> for more detailed instructions about the plugin.\u003C\u002Fp>\n\u003Ch4>Download & Install CRM add-ons\u003C\u002Fh4>\n\u003Cp>You can choose one from the list of add-ons for CRMs like Zoho CRM, Zoho CRM Plus, Salesforce, Freshsales, Vtiger CRM & SugarCRM. If you’re a SuiteCRM or Joforce CRM user, you don’t require an add-on to install.\u003C\u002Fp>\n\u003Cp>Install and activate both WP Leads Builder For CRM and the respective CRM add-on below:\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwp-zoho-crm\u002F\" rel=\"ugc\">Zoho CRM & Zoho CRM Plus\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwp-salesforce\u002F\" rel=\"ugc\">Salesforce\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwp-sugar-free\u002F\" rel=\"ugc\">SugarCRM\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwp-freshsales\u002F\" rel=\"ugc\">Freshsales\u003C\u002Fa>\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fwp-tiger\u002F\" rel=\"ugc\">Vtiger CRM\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch4>Third-Party Form Builder Plugins Integration\u003C\u002Fh4>\n\u003Cp>Leads Builder for Any CRM supports using existing forms created with popular form builders like\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Contact Form 7\u003C\u002Fli>\n\u003Cli>WP Forms(free & pro)\u003C\u002Fli>\n\u003Cli>Caldera Forms\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>PRO FEATURES\u003C\u002Fh4>\n\u003Cp>Upgrade to the Leads Builder Pro version and unlock advanced features, including:\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Sync as CRM contacts\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Send your website visitors information from forms to your CRM as Contacts for efficient followups.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Enhanced WordPress Integration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Sync WordPress users and data collected from forms as either contacts or leads.\u003C\u002Fli>\n\u003Cli>Sync existing WordPress users with a one-time sync option as leads or contacts.\u003C\u002Fli>\n\u003Cli>Sync custom fields created with MemberPress, WP-Members, and ACF under the WordPress Users module with leads and contacts in your CRM.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>WooCommerce Integration\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Send checkout information and capture abandoned cart customers as CRM leads.\u003C\u002Fli>\n\u003Cli>Gain valuable insights into your visitors’ WooCommerce journey on your website.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Third-Party Form Builder Support\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Integrate with popular form builders such as Ninja Forms, Gravity Forms, and Contact Form 7.\u003C\u002Fli>\n\u003Cli>Easily sync data from these forms with your CRM.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Advanced CRM Lead Conversion\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Convert WordPress Users into potential leads or contacts of your CRM system with ease.\u003C\u002Fli>\n\u003Cli>Synchronize both existing and newly registered users for a seamless lead management experience.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Efficient Data Handling\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Create, update, or skip options to handle duplicate entries effectively.\u003C\u002Fli>\n\u003Cli>Implement Google Captcha to prevent spam submissions and maintain data accuracy.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Unlimited Form Creations\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Easily create and manage an unlimited number of forms, tailoring your lead capture process to your specific needs.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Watch Our Video Tutorials\u003C\u002Fstrong>\u003Cbr \u002F>\nExplore our YouTube playlist containing informative tutorials on WP Leads Builder for CRM plugin.\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fwww.youtube.com\u002Fwatch?v=wmlyERJmYXw&list=PL2k3Ck1bFtbSptSNMIhr_TaNj-qjHiTio&index=1&utm_source=wordpress_org&utm_medium=readme&utm_campaign=lead_builder_free\" rel=\"nofollow ugc\">Watch Video Tutorials\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>Visit our website, to upgrade to the \u003Ca href=\"https:\u002F\u002Fwww.smackcoders.com\u002Fwp-leads-builder-any-crm-pro.html?utm_source=wordpress_org&utm_medium=readme&utm_campaign=lead_builder_free\" rel=\"nofollow ugc\">Leads Builder For Any CRM Pro\u003C\u002Fa> today.\u003C\u002Fp>\n\u003Cp>For more detailed instructions, check out our \u003Ca href=\"https:\u002F\u002Fwww.smackcoders.com\u002Fdocumentation\u002Fleads-builder-for-any-crm-from-wordpress-pro\u002Flead-builder-for-any-crm?utm_source=lead_builder_free&utm_campaign=readme&utm_medium=wp_org\" rel=\"nofollow ugc\">Leads Builder for CRM Pro documentation\u003C\u002Fa>.\u003C\u002Fp>\n","Convert contact forms data into leads or contacts directly to one of your favourite CRM.",400,83982,80,46,"2025-06-30T07:56:00.000Z","6.8.5","5.0",[20,21,136,137,138],"leads","webform-to-lead","wordpress-to-lead","https:\u002F\u002Fwww.smackcoders.com\u002Fwp-leads-builder-any-crm-pro.html","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-leads-builder-any-crm.3.2.zip",96,3,0,"2025-07-01 00:00:00",{"slug":146,"name":147,"version":148,"author":149,"author_profile":150,"description":151,"short_description":152,"active_installs":153,"downloaded":154,"rating":143,"num_ratings":143,"last_updated":155,"tested_up_to":156,"requires_at_least":134,"requires_php":157,"tags":158,"homepage":162,"download_link":163,"security_score":164,"vuln_count":143,"unpatched_count":143,"last_vuln_date":37,"fetched_at":30},"download-magnet","Download Magnet","2.5.3","Peachy Software","https:\u002F\u002Fprofiles.wordpress.org\u002Fpeachysoftware\u002F","\u003Cp>This plugin provides an easy-to-use way of capturing email addresses when the end user wishes to download a file. Is used as a shortcode in your posts or pages.\u003C\u002Fp>\n\u003Ch4>Features:\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Is easy to use\u003C\u002Fli>\n\u003Cli>Can be used to capture email addresses inline or from a button.\u003C\u002Fli>\n\u003Cli>Can now use an existing button on the page to keep the styling intact.\u003C\u002Fli>\n\u003Cli>Multiple entries can be created.\u003C\u002Fli>\n\u003Cli>A block for the Block Editor (Gutenberg) is available.\u003C\u002Fli>\n\u003Cli>Allows capture of an email address when offering a download as a lead magnet.\u003C\u002Fli>\n\u003Cli>Contacts can be downloaded (CSV file) to import into your email marketing system.\u003C\u002Fli>\n\u003Cli>An ProPak Addon (paid) is available to directly send contacts to your email marketing provider. \u003Ca href=\"https:\u002F\u002Fpeachysoftware.com\u002Fdownloadmagnet\u002Faddons\" rel=\"nofollow ugc\">Download Magnet Addons\u003C\u002Fa>\n\u003Cul>\n\u003Cli>Currently supports ActiveCampaign, Kit, MailerLite, MailPoet, MailChimp, SendFox, Sendy and Webhooks. More in development.\u003C\u002Fli>\n\u003Cli>The Webhook connects to any system that supports webhooks such as Zapier, Make (Integromat) and Automate.io etc.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>Custom options include to request name and also GDPR consent.\u003C\u002Fli>\n\u003Cli>Utilizes the wp_footer action to ensure the dialog box is always on top. (Can be overriden).\u003C\u002Fli>\n\u003Cli>Please send me your feedback  \u003Ca href=\"http:\u002F\u002Fpeachysoftware.com\u002Fcontact\u002F\" rel=\"nofollow ugc\">here\u003C\u002Fa> for any new features you want to see in next version of this plugin.I will be happy to receive feedback.\u003C\u002Fli>\n\u003C\u002Ful>\n","This plugin provides an easy-to-use way of capturing email addresses when the end user wishes to download a file.",90,2436,"2025-12-30T13:30:00.000Z","6.9.4","7.0",[159,160,21,22,161],"download","email-capture","marketing","https:\u002F\u002Fpeachysoftware.com\u002Fdownloadmagnet","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdownload-magnet.2.5.3.zip",100,{"slug":166,"name":167,"version":168,"author":169,"author_profile":170,"description":171,"short_description":172,"active_installs":173,"downloaded":174,"rating":143,"num_ratings":143,"last_updated":18,"tested_up_to":133,"requires_at_least":175,"requires_php":176,"tags":177,"homepage":18,"download_link":183,"security_score":164,"vuln_count":143,"unpatched_count":143,"last_vuln_date":37,"fetched_at":184},"wcc-cf7-to-brevo","WCC CF7 to Brevo","1.1.0","weconnectcodeplugins","https:\u002F\u002Fprofiles.wordpress.org\u002Fweconnectcodeplugins\u002F","\u003Cp>Contact Form 7 Brevo Plugin sends form submissions from \u003Ca href=\"https:\u002F\u002Fcontactform7.com\u002F\" rel=\"nofollow ugc\">Contact Form 7\u003C\u002Fa> plugins to Brevo when someone submits a form. Learn more about Contact Form 7 Brevo Plugin at \u003Ca href=\"https:\u002F\u002Fwww.weconnectcode.com\u002Fplugin\u002Fbrevo-for-contact-form-7\" rel=\"nofollow ugc\">weconnectcode.com\u003C\u002Fa>. We also offer other connector for Clio \u003Ca href=\"https:\u002F\u002Fwww.weconnectcode.com\u002Fplugin\u002Fclio-grow-for-contact-form-7\" rel=\"nofollow ugc\">Contact Form 7 Clio Integration\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>License\u003C\u002Fh3>\n\u003Cp>GPLv2 or later\u003C\u002Fp>\n\u003Ch3>How to Setup\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Go to “Brevo Accounts” tab then add new account.\u003C\u002Fli>\n\u003Cli>Go to “Brevo Integration” tab then create new Integration.\u003C\u002Fli>\n\u003Cli>Map required Brevo fields to contact form 7 fields.\u003C\u002Fli>\n\u003Cli>Send your test entry to Brevo by submiting contact form 7.\u003C\u002Fli>\n\u003Cli>Go to “Brevo Logs” tab and verify, if entry was sent to Brevo.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Connect Brevo account\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Connect any contact form 7 to Brevo account by safe and secure Oauth 2.0.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Map Brevo fields\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>First select any Brevo object then Map contact form fields to Brevo object fields. There is No limitation on number of fields. You can map unlimited fields.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Filter contact form 7 submissions\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Either Send all contact form 7 submissions to Brevo or filter contact form submissions sent to Brevo based on user input. For example , send only those entries to Brevo which have work email address.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Manually send to Brevo\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Send contact form 7 submissions to Brevo when someone submits a contact form. You can manually send contact form submissions to Brevo.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Brevo logs\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>View a detailed log of each contact form 7 submission whether sent (or not sent) to Brevo and easily resend any contact form submission to Brevo.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Send Data As Brevo object Notes\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Send one to many contact form fields as Brevo object notes when anyone submits a form on your site.\u003C\u002Fp>\n\u003Ch3>Why we built this plugin\u003C\u002Fh3>\n\u003Cp>Contact Form 7 and some other popular contact forms are good but you can not send contact form submissions to any crm including Brevo. You can send any contact form submissions from your wordpress site to Brevo with this free wordpress Brevo plugin.\u003C\u002Fp>\n\u003Cblockquote>\u003Cp>\u003Cstrong>Premium Version Features.\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>This plugin has a Premium version which comes with several additional benifits \u003Ca href=\"https:\u002F\u002Fwww.weconnectcode.com\u002Fplugin\u002Fbrevo-for-contact-form-7\" rel=\"nofollow ugc\">Contact Form 7 – Brevo\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Brevo Custom fields and Particularly Phone Fields.\u003C\u002Fli>\n\u003Cli>Brevo Notes Field\u003C\u002Fli>\n\u003Cli>User Agent and IP related Data Of the Entries\u003C\u002Fli>\n\u003Cli>WCC Entries Pro Version With all the Premium Features.\u003C\u002Fli>\n\u003Cli>Super Helpful WCC Addons and Free Updates.\u003C\u002Fli>\n\u003Cli>By Purchasing the Premium Version of the Plugin, You will Get Free Updates\u003C\u002Fli>\n\u003Cli>Get Pro Support\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fblockquote>\n\u003Ch3>Want to send data to other crm\u003C\u002Fh3>\n\u003Cp>We have Premium Extensions for 20+ CRMs.\u003Ca href=\"https:\u002F\u002Fweconnectcode.com\u002Fplugins\" rel=\"nofollow ugc\">View All CRM Extensions\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch3>Contact Form 7 Brevo Integration\u003C\u002Fh3>\n\u003Cp>We have a separate plugin for Brevo. \u003Ca href=\"https:\u002F\u002Fwww.weconnectcode.com\u002Fplugin\u002Fbrevo-for-contact-form-7\" rel=\"nofollow ugc\">Contact Form 7 Brevo\u003C\u002Fa>\u003C\u002Fp>\n","Send Contact Form 7 Plugin Submissions to Brevo.",10,278,"4.7","7.2",[178,179,180,181,182],"brevo","contact-form-7-brevo","contact-form-7-brevo-web-to-lead","wordpress-brevo","wordpress-brevo-integration","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwcc-cf7-to-brevo.zip","2026-03-15T10:48:56.248Z",{"slug":186,"name":187,"version":188,"author":189,"author_profile":190,"description":191,"short_description":192,"active_installs":143,"downloaded":193,"rating":164,"num_ratings":28,"last_updated":194,"tested_up_to":133,"requires_at_least":195,"requires_php":196,"tags":197,"homepage":18,"download_link":201,"security_score":164,"vuln_count":143,"unpatched_count":143,"last_vuln_date":37,"fetched_at":30},"aii-cx-widget","Aii.cx – Embeddable AI Tools & Lead Magnets","1.0.0","aiicx","https:\u002F\u002Fprofiles.wordpress.org\u002Faiicx\u002F","\u003Cp>Aii.cx is a no-code platform that spins up custom prompt powered AI-forms in 30 seconds, embedding them directly onto website to collect extra leads without touching the core conversion path — while also boosting SEO and user engagement, providing instant value to your customers.\u003C\u002Fp>\n\u003Ch4>Full White‑Label Control\u003C\u002Fh4>\n\u003Cp>Map widgets to custom domains, swap colors and logos, inject custom CSS, and even resell the tools to your own clients — set any price you like and keep 100% of the revenue.\u003C\u002Fp>\n\u003Ch4>Easy to Create\u003C\u002Fh4>\n\u003Cp>A built‑in AI assistant instantly turns a short business description into a ready‑to‑use widget by suggesting ideas, fields and prompt. Prefer full control? Build manually with our visual editor — no coding needed.\u003C\u002Fp>\n\u003Ch4>Native Integrations\u003C\u002Fh4>\n\u003Cp>Native Zapier hooks, webhooks, and segment-ready events push leads and submissions into any CRM instantly.\u003C\u002Fp>\n\u003Ch4>Built‑In Analytics\u003C\u002Fh4>\n\u003Cp>Track impressions, completions and incremental conversions right in the dashboard — understand exactly how many extra leads each widget drives.\u003C\u002Fp>\n\u003Ch4>SEO & Engagement Boost\u003C\u002Fh4>\n\u003Cp>Google‑friendly markup keeps pages crawlable, while conversational widgets lift dwell time and cut bounce rates.\u003C\u002Fp>\n\u003Cp>Stop leaking opportunity. Deploy AI experiences that capture more leads, strengthen rankings and delight visitors — grab the Aii.cx WordPress plugin today!\u003C\u002Fp>\n\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FnZOQReWMK7M?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Cp>Note: On the free plan, the embedded widget will display a small “Powered by Aii.cx” label. This can be removed by upgrading to any paid plan.\u003C\u002Fp>\n\u003Ch3>Usage\u003C\u002Fh3>\n\u003Col>\n\u003Cli>Go to https:\u002F\u002Faii.cx\u002F and click “Start free”.\u003C\u002Fli>\n\u003Cli>Follow the instructions — this will create your account and your first tool.\u003C\u002Fli>\n\u003Cli>After creating it, you can start testing and customizing your tool — edit styles, prompt, fields, and lead collection strategy.\u003C\u002Fli>\n\u003Cli>If you’re not happy with this tool, go to the main page at https:\u002F\u002Faii.cx\u002Fapp\u002Fforms and click “Create new tool.” You can either build a new tool from scratch manually (set up fields, prompt, and lead collection strategy) or use the AI assistant again.\u003C\u002Fli>\n\u003Cli>When your tool is ready, click Publish \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Share URL, then copy the tool ID from the link (e.g. in https:\u002F\u002Faii.cx\u002Fapp\u002Fforms\u002Fshare\u002Ff0b8d029-4d7b-4eee-b44d-6abfdb579048 your ID is f0b8d029-4d7b-4eee-b44d-6abfdb579048).\u003C\u002Fli>\n\u003Cli>In WordPress, create or edit a page or post.\u003C\u002Fli>\n\u003Cli>Paste the shortcode where you want the widget to appear: \u003Ccode>[aiicx_widget id=YOUR_WIDGET_ID]\u003C\u002Fcode> (e.g. [aiicx_widget id=f0b8d029-4d7b-4eee-b44d-6abfdb579048]).\u003C\u002Fli>\n\u003Cli>Publish the WordPress content, and your AI tool will immediately start capturing leads and delivering instant value to your clients.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Development\u003C\u002Fh3>\n\u003Cp>The production bundle \u003Ccode>\u002Fjs\u002Faiicx-widget.min.js\u003C\u002Fcode> is built from human-readable ES-module sources.\u003C\u002Fp>\n\u003Cp>Source code: https:\u002F\u002Fgithub.com\u002Ftitaev\u002Faii-widget-frontend-preact.git\u003C\u002Fp>\n\u003Cp>Build prerequisites\u003Cbr \u002F>\n* Node v18.12.1\u003Cbr \u002F>\n* npm v8.19.2\u003C\u002Fp>\n\u003Cp>Clone and build:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>git clone https:\u002F\u002Fgithub.com\u002Ftitaev\u002Faii-widget-frontend-preact.git\ncd aii-widget-frontend-preact\nnpm install\nnpm run build:prod       # builds dist\u002Faii-cx-widget-v3.prod.js, which is copied to js\u002Faiicx-widget.min.js for distribution\u003Ch3>Third-Party Libraries\u003C\u002Fh3>\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>This plugin (js\u002Faiicx-widget.min.js) bundles the following MIT-licensed libraries:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fpreactjs\u002Fpreact\" rel=\"nofollow ugc\">preact\u003C\u002Fa> (^10.22.0)\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fpreactjs\u002Fsignals\" rel=\"nofollow ugc\">@preact\u002Fsignals\u003C\u002Fa> (^1.2.3)\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fmarkdown-it\u002Fmarkdown-it\" rel=\"nofollow ugc\">markdown-it\u003C\u002Fa> (^14.1.0)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Upgrade to Pro\u003C\u002Fh3>\n\u003Cp>This plugin is free, but premium features, white-label options, more\u002Funlimited credits and priority support are available at:\u003C\u002Fp>\n\u003Cp>https:\u002F\u002Faii.cx\u002F\u003C\u002Fp>\n\u003Cp>Compare plans and features:\u003Cbr \u002F>\nhttps:\u002F\u002Faii.cx\u002Fpricing.php\u003C\u002Fp>\n\u003Ch3>Support\u003C\u002Fh3>\n\u003Cp>For free community support, please use:\u003Cbr \u002F>\nhttps:\u002F\u002Fwordpress.org\u002Fsupport\u002Fplugin\u002Faii-cx-widget\u002F\u003C\u002Fp>\n\u003Cp>For priority or SLA-backed support:\u003Cbr \u002F>\nhttps:\u002F\u002Faii.cx\u002Fcontact.php\u003C\u002Fp>\n","Capture more leads, boost SEO, and deliver instant value — embed white-label AI forms and tools via shortcode, no code needed.",1517,"2025-05-13T20:26:00.000Z","5.6","7.4",[198,199,200,21,22],"ai-lead-magnet","ai-tools","ai-widget","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Faii-cx-widget.zip",{"slug":203,"name":204,"version":205,"author":124,"author_profile":125,"description":206,"short_description":207,"active_installs":143,"downloaded":208,"rating":143,"num_ratings":143,"last_updated":209,"tested_up_to":210,"requires_at_least":134,"requires_php":18,"tags":211,"homepage":18,"download_link":212,"security_score":213,"vuln_count":143,"unpatched_count":143,"last_vuln_date":37,"fetched_at":30},"crm-connector-plus","CRM Connector Plus","0.1","\u003Cp>CRM Connector Plus enables to capture Webforms to your CRM as Leads,Contacts,Products and SalesOrder.Embed forms as Posts & Widgets.\u003C\u002Fp>\n\u003Ch4>Highlighted features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>Data Bucket – Stores All Form, Users and WooCommerce Related Details based on Data Bucket Mapping.\u003C\u002Fli>\n\u003Cli>Generate forms with or without 3rd party web form.\u003C\u002Fli>\n\u003Cli>Embed forms in Page, Post or Widgets to capture CRM Lead.\u003C\u002Fli>\n\u003Cli>Captures potential leads to CRM.\u003C\u002Fli>\n\u003Cli>Redirects User to desired page after successful form submission.\u003C\u002Fli>\n\u003Cli>Notification on success or failure of Lead capture.\u003C\u002Fli>\n\u003Cli>Converts new Users as your CRM Contact. \u003C\u002Fli>\n\u003Cli>Supports JoForce CRM.\u003C\u002Fli>\n\u003Cli>Sends Email Notification for Form Entries\u003C\u002Fli>\n\u003Cli>Customize Default Form.\u003C\u002Fli>\n\u003Cli>Customize the message shown on form submission.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Premium Addons\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>CRM ADDONS\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Zoho CRM Pro Plus\u003C\u002Fli>\n\u003Cli>Vtiger Pro Plus\u003C\u002Fli>\n\u003Cli>Sugar Pro Plus\u003C\u002Fli>\n\u003Cli>Salesforce Pro Plus\u003C\u002Fli>\n\u003Cli>Suite CRM Pro Plus\u003C\u002Fli>\n\u003Cli>Freshsales Pro Plus\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>CRM Addons – Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Captures Leads, Contacts, Products and SalesOrder.\u003C\u002Fli>\n\u003Cli>Provided support for .com, .in and .eu domains (Zoho CRM)\u003C\u002Fli>\n\u003Cli>Users can move existing and new users to CRM modules via User Sync Addon.\u003C\u002Fli>\n\u003Cli>Users can sync both existing and new WooCommerce Products and Orders to CRM Products and SalesOrder,leads and contacts through  WooCommerce Sync Addon.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>HELPDESK ADDONS\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>FreshDesk Pro Plus\u003C\u002Fli>\n\u003Cli>Zendesk Pro Plus\u003C\u002Fli>\n\u003Cli>Vtiger Ticket Pro Plus\u003C\u002Fli>\n\u003Cli>Zoho Desk Pro Plus\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>HELPDESK Addons – Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Captures Tickets and Contacts.\u003C\u002Fli>\n\u003Cli>Addon users can move existing and new users to Helpdesk modules through User Sync Addon.\u003C\u002Fli>\n\u003Cli>Zoho Desk provides support for .com and .eu domains.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>FORM ADDONS\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Ninja Form WP Pro Plus\u003C\u002Fli>\n\u003Cli>Qu Form Pro Plus\u003C\u002Fli>\n\u003Cli>Gravity Form Pro Plus\u003C\u002Fli>\n\u003Cli>Contact Form Pro Plus\u003C\u002Fli>\n\u003Cli>Caldera Form Pro Plus\u003C\u002Fli>\n\u003Cli>WP Form Pro Plus\u003C\u002Fli>\n\u003Cli>Leads Multi Forms Pro Plus\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Form Addons – Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Create your own Lead\u002FContact form or Use existing webforms to capture your visitor info right inside your CRM. \u003C\u002Fli>\n\u003Cli>Generate unlimited shortcodes and inject inside your post, pages and widgets.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>*WooCommerce Addon**\u003C\u002Fp>\n\u003Cul>\n\u003Cli>On enabling Woocommerce Manual Sync option, existing products \u002F orders get synced with configured crm products or SalesOrder.\u003C\u002Fli>\n\u003Cli>On enabling User Auto Sync option, new products and orders get synced on creation.\u003C\u002Fli>\n\u003Cli>Provides support for Create, Update and Skip.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>*Users Addon**\u003C\u002Fp>\n\u003Cul>\n\u003Cli>On enabling User Manual Sync option, existing users get synced with configured crm \u002F helpdesk modules.\u003C\u002Fli>\n\u003Cli>On enabling User Auto Sync option, new users get synced on creation.\u003C\u002Fli>\n\u003C\u002Ful>\n","WordPress to CRM\u002FHelpdesk Integration.",1115,"2021-02-27T06:00:00.000Z","5.6.17",[20,21,136,137,138],"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcrm-connector-plus.0.1.zip",85,{"attackSurface":215,"codeSignals":286,"taintFlows":395,"riskAssessment":940,"analyzedAt":953},{"hooks":216,"ajaxHandlers":261,"restRoutes":278,"shortcodes":279,"cronEvents":284,"entryPointCount":285,"unprotectedCount":143},[217,223,227,233,238,242,247,251,254,257],{"type":218,"name":219,"callback":220,"file":221,"line":222},"action","admin_menu","zcfadminenus","includes\\crmconfigdefault.php",179,{"type":218,"name":224,"callback":225,"file":226,"line":27},"wpcf7_before_send_mail","zcfcontact_forms_submitdata","includes\\crmcontactform7.php",{"type":228,"name":229,"callback":230,"file":231,"line":232},"filter","widget_text","do_shortcode","includes\\crmcontactformgenerator.php",17,{"type":218,"name":234,"callback":235,"file":236,"line":237},"WPfile_update","zcf_capture_updating_users","index.php",136,{"type":218,"name":239,"callback":240,"file":236,"line":241},"admin_head","zcf_add_nonce",202,{"type":218,"name":243,"callback":244,"priority":245,"file":236,"line":246},"admin_enqueue_scripts","zcf_plugin_assets",20,203,{"type":218,"name":248,"callback":249,"priority":245,"file":236,"line":250},"wp_enqueue_scripts","zcf_frontend_enabledefault",228,{"type":218,"name":248,"callback":252,"file":236,"line":253},"zcf_frondendcustom",237,{"type":218,"name":239,"callback":255,"file":236,"line":256},"zcf_adminhelpenable",252,{"type":228,"name":258,"callback":259,"file":236,"line":260},"http_request_args","closure",253,[262,269,272,275],{"action":263,"nopriv":264,"callback":265,"hasNonce":266,"hasCapCheck":264,"file":267,"line":268},"mainActionscrmForms",false,"zcfmainFormsActions",true,"includes\\crmcustomfunctions.php",575,{"action":270,"nopriv":264,"callback":270,"hasNonce":266,"hasCapCheck":264,"file":267,"line":271},"zcf_updateTitles1",631,{"action":273,"nopriv":264,"callback":273,"hasNonce":266,"hasCapCheck":264,"file":267,"line":274},"zcf_updateTitles",634,{"action":276,"nopriv":264,"callback":276,"hasNonce":266,"hasCapCheck":264,"file":267,"line":277},"zcf_getModuleLayoutlist",637,[],[280],{"tag":281,"callback":282,"file":231,"line":283},"zohocrm-web-form","zcf_ContactFormFieldsGenerator",18,[],5,{"dangerousFunctions":287,"sqlUsage":309,"outputEscaping":318,"fileOperations":28,"externalRequests":389,"nonceChecks":390,"capabilityChecks":143,"bundledLibraries":391},[288,292,296,299,302,306],{"fn":289,"file":231,"line":290,"context":291},"unserialize",485,"$defaultvaluepicklist = unserialize($config_fields[$i]['defaultvalue'],['allowed_classes' => false])",{"fn":289,"file":293,"line":294,"context":295},"includes\\crmshortcodefunctions.php",183,"$defaultvaluepicklist = unserialize($config_leads_fields['fields'][$i]['defaultvalue'],['allowed_cla",{"fn":289,"file":293,"line":297,"context":298},867,"$cont_array = unserialize($value->custom_field_values, ['allowed_classes' => false]);",{"fn":289,"file":293,"line":300,"context":301},880,"$cont_array = unserialize($value->defaultvalues,['allowed_classes' => false]);",{"fn":289,"file":303,"line":304,"context":305},"includes\\crmwebformsfieldsmapping.php",374,"$crmFields['fields'][$i]['defaultvalue'] = array('defaultvalues' => @unserialize($newfields->default",{"fn":289,"file":303,"line":307,"context":308},378,"$crmFields['fields'][$i]['type'] = array('picklistValues' => @unserialize($newfields->custom_field_v",{"prepared":310,"raw":311,"locations":312},219,2,[313,316],{"file":293,"line":314,"context":315},483,"$wpdb->query() with variable interpolation",{"file":293,"line":317,"context":315},970,{"escaped":319,"rawEcho":320,"locations":321},608,31,[322,325,327,330,333,335,337,339,341,343,345,347,349,351,353,356,358,360,362,364,366,368,370,372,374,376,378,380,382,384,387],{"file":221,"line":323,"context":324},154,"raw output",{"file":221,"line":326,"context":324},167,{"file":328,"line":329,"context":324},"includes\\crmcontactformfields.php",84,{"file":331,"line":332,"context":324},"includes\\crmsettingstab.php",41,{"file":331,"line":334,"context":324},45,{"file":331,"line":336,"context":324},61,{"file":331,"line":338,"context":324},76,{"file":331,"line":340,"context":324},86,{"file":331,"line":342,"context":324},93,{"file":331,"line":344,"context":324},110,{"file":331,"line":346,"context":324},114,{"file":331,"line":348,"context":324},131,{"file":331,"line":350,"context":324},135,{"file":331,"line":352,"context":324},144,{"file":354,"line":355,"context":324},"includes\\crmwebformfields.php",137,{"file":354,"line":357,"context":324},139,{"file":354,"line":359,"context":324},193,{"file":354,"line":361,"context":324},224,{"file":354,"line":363,"context":324},238,{"file":354,"line":365,"context":324},251,{"file":354,"line":367,"context":324},331,{"file":354,"line":369,"context":324},352,{"file":354,"line":371,"context":324},360,{"file":354,"line":373,"context":324},370,{"file":354,"line":375,"context":324},393,{"file":354,"line":377,"context":324},419,{"file":354,"line":379,"context":324},431,{"file":354,"line":381,"context":324},454,{"file":354,"line":383,"context":324},455,{"file":385,"line":386,"context":324},"includes\\crmwebforms.php",166,{"file":385,"line":388,"context":324},168,9,15,[392],{"name":393,"version":37,"knownCves":394},"Select2",[],[396,423,434,447,459,469,478,489,499,529,548,579,589,599,610,619,631,672,695,760,782,800,883],{"entryPoint":397,"graph":398,"unsanitizedCount":143,"severity":422},"zcfcontact_forms_submitdata (includes\\crmcontactform7.php:39)",{"nodes":399,"edges":419},[400,405,411,414],{"id":401,"type":402,"label":403,"file":226,"line":404},"n0","source","$_POST (x4)",42,{"id":406,"type":407,"label":408,"file":226,"line":409,"wp_function":410},"n1","sink","get_results() [SQLi]",63,"get_results",{"id":412,"type":402,"label":413,"file":226,"line":404},"n2","$_POST",{"id":415,"type":407,"label":416,"file":226,"line":417,"wp_function":418},"n3","get_var() [SQLi]",157,"get_var",[420,421],{"from":401,"to":406,"sanitized":266},{"from":412,"to":415,"sanitized":266},"low",{"entryPoint":424,"graph":425,"unsanitizedCount":143,"severity":422},"\u003Ccrmcontactform7> (includes\\crmcontactform7.php:0)",{"nodes":426,"edges":431},[427,428,429,430],{"id":401,"type":402,"label":403,"file":226,"line":404},{"id":406,"type":407,"label":408,"file":226,"line":409,"wp_function":410},{"id":412,"type":402,"label":413,"file":226,"line":404},{"id":415,"type":407,"label":416,"file":226,"line":417,"wp_function":418},[432,433],{"from":401,"to":406,"sanitized":266},{"from":412,"to":415,"sanitized":266},{"entryPoint":435,"graph":436,"unsanitizedCount":28,"severity":422},"zcfmaping_contactform_fields (includes\\crmcontactformfieldsmapping.php:200)",{"nodes":437,"edges":445},[438,441],{"id":401,"type":402,"label":439,"file":440,"line":241},"$_REQUEST","includes\\crmcontactformfieldsmapping.php",{"id":406,"type":407,"label":442,"file":440,"line":443,"wp_function":444},"update_option() [Settings Manipulation]",255,"update_option",[446],{"from":401,"to":406,"sanitized":264},{"entryPoint":448,"graph":449,"unsanitizedCount":458,"severity":422},"zcf_saveClientAuthKeys (includes\\crmcustomfunctions.php:109)",{"nodes":450,"edges":456},[451,454],{"id":401,"type":402,"label":452,"file":267,"line":453},"$_REQUEST (x4)",111,{"id":406,"type":407,"label":442,"file":267,"line":455,"wp_function":444},115,[457],{"from":401,"to":406,"sanitized":264},4,{"entryPoint":460,"graph":461,"unsanitizedCount":28,"severity":422},"zcfmappingmoduleconf (includes\\crminterfunction.php:130)",{"nodes":462,"edges":467},[463,465],{"id":401,"type":402,"label":439,"file":464,"line":348},"includes\\crminterfunction.php",{"id":406,"type":407,"label":442,"file":464,"line":466,"wp_function":444},132,[468],{"from":401,"to":406,"sanitized":264},{"entryPoint":470,"graph":471,"unsanitizedCount":28,"severity":422},"zcfsaveSyncValue (includes\\crminterfunction.php:136)",{"nodes":472,"edges":476},[473,475],{"id":401,"type":402,"label":439,"file":464,"line":474},138,{"id":406,"type":407,"label":442,"file":464,"line":357,"wp_function":444},[477],{"from":401,"to":406,"sanitized":264},{"entryPoint":479,"graph":480,"unsanitizedCount":143,"severity":422},"zcf_save_contact_form_title (includes\\crminterfunction.php:179)",{"nodes":481,"edges":487},[482,485],{"id":401,"type":402,"label":483,"file":464,"line":484},"$_REQUEST (x2)",185,{"id":406,"type":407,"label":442,"file":464,"line":486,"wp_function":444},187,[488],{"from":401,"to":406,"sanitized":266},{"entryPoint":490,"graph":491,"unsanitizedCount":28,"severity":422},"zcf_save_usersync_option (includes\\crminterfunction.php:223)",{"nodes":492,"edges":497},[493,495],{"id":401,"type":402,"label":439,"file":464,"line":494},225,{"id":406,"type":407,"label":442,"file":464,"line":496,"wp_function":444},226,[498],{"from":401,"to":406,"sanitized":264},{"entryPoint":500,"graph":501,"unsanitizedCount":143,"severity":422},"zcfformFields (includes\\crmshortcodefunctions.php:114)",{"nodes":502,"edges":524},[503,506,509,512,513,517,519,521],{"id":401,"type":402,"label":504,"file":293,"line":505},"$_REQUEST['module']",407,{"id":406,"type":407,"label":507,"file":293,"line":505,"wp_function":508},"echo() [XSS]","echo",{"id":412,"type":402,"label":510,"file":293,"line":511},"$_REQUEST['EditShortcode']",409,{"id":415,"type":407,"label":507,"file":293,"line":511,"wp_function":508},{"id":514,"type":402,"label":515,"file":293,"line":516},"n4","$_REQUEST['onAction']",410,{"id":518,"type":407,"label":507,"file":293,"line":516,"wp_function":508},"n5",{"id":520,"type":402,"label":439,"file":293,"line":496},"n6",{"id":522,"type":407,"label":507,"file":293,"line":523,"wp_function":508},"n7",472,[525,526,527,528],{"from":401,"to":406,"sanitized":266},{"from":412,"to":415,"sanitized":266},{"from":514,"to":518,"sanitized":266},{"from":520,"to":522,"sanitized":266},{"entryPoint":530,"graph":531,"unsanitizedCount":143,"severity":422},"\u003Ccrmwebformgloablsetting> (includes\\crmwebformgloablsetting.php:0)",{"nodes":532,"edges":544},[533,536,537,540,541,542],{"id":401,"type":402,"label":403,"file":534,"line":535},"includes\\crmwebformgloablsetting.php",57,{"id":406,"type":407,"label":442,"file":534,"line":336,"wp_function":444},{"id":412,"type":402,"label":538,"file":534,"line":539},"$_SERVER['REQUEST_URI']",82,{"id":415,"type":407,"label":507,"file":534,"line":539,"wp_function":508},{"id":514,"type":402,"label":413,"file":534,"line":535},{"id":518,"type":407,"label":507,"file":534,"line":543,"wp_function":508},129,[545,546,547],{"from":401,"to":406,"sanitized":266},{"from":412,"to":415,"sanitized":266},{"from":514,"to":518,"sanitized":266},{"entryPoint":549,"graph":550,"unsanitizedCount":142,"severity":83},"\u003Ccrmcontactformfields> (includes\\crmcontactformfields.php:0)",{"nodes":551,"edges":573},[552,554,556,558,559,562,563,566,568,571],{"id":401,"type":402,"label":483,"file":328,"line":553},8,{"id":406,"type":407,"label":408,"file":328,"line":555,"wp_function":410},35,{"id":412,"type":402,"label":557,"file":328,"line":26},"$_REQUEST['third_module'] (x2)",{"id":415,"type":407,"label":507,"file":328,"line":26,"wp_function":508},{"id":514,"type":402,"label":560,"file":328,"line":561},"$_REQUEST['layoutname'] (x2)",68,{"id":518,"type":407,"label":507,"file":328,"line":561,"wp_function":508},{"id":520,"type":402,"label":564,"file":328,"line":565},"$_REQUEST (x5)",69,{"id":522,"type":407,"label":507,"file":328,"line":567,"wp_function":508},70,{"id":569,"type":402,"label":439,"file":328,"line":570},"n8",83,{"id":572,"type":407,"label":507,"file":328,"line":329,"wp_function":508},"n9",[574,575,576,577,578],{"from":401,"to":406,"sanitized":264},{"from":412,"to":415,"sanitized":266},{"from":514,"to":518,"sanitized":266},{"from":520,"to":522,"sanitized":266},{"from":569,"to":572,"sanitized":264},{"entryPoint":580,"graph":581,"unsanitizedCount":28,"severity":83},"zcfget_contactform_fields (includes\\crmcontactformfieldsmapping.php:68)",{"nodes":582,"edges":587},[583,585],{"id":401,"type":402,"label":439,"file":440,"line":584},72,{"id":406,"type":407,"label":408,"file":440,"line":586,"wp_function":410},94,[588],{"from":401,"to":406,"sanitized":264},{"entryPoint":590,"graph":591,"unsanitizedCount":28,"severity":83},"zcf_mapped_fields_config (includes\\crmcontactformfieldsmapping.php:260)",{"nodes":592,"edges":597},[593,595],{"id":401,"type":402,"label":439,"file":440,"line":594},264,{"id":406,"type":407,"label":408,"file":440,"line":596,"wp_function":410},293,[598],{"from":401,"to":406,"sanitized":264},{"entryPoint":600,"graph":601,"unsanitizedCount":142,"severity":83},"\u003Ccrmcontactformfieldsmapping> (includes\\crmcontactformfieldsmapping.php:0)",{"nodes":602,"edges":607},[603,604,605,606],{"id":401,"type":402,"label":483,"file":440,"line":584},{"id":406,"type":407,"label":408,"file":440,"line":586,"wp_function":410},{"id":412,"type":402,"label":439,"file":440,"line":241},{"id":415,"type":407,"label":442,"file":440,"line":443,"wp_function":444},[608,609],{"from":401,"to":406,"sanitized":264},{"from":412,"to":415,"sanitized":264},{"entryPoint":611,"graph":612,"unsanitizedCount":28,"severity":83},"zcf_selectLayoutName (includes\\crmcustomfunctions.php:94)",{"nodes":613,"edges":617},[614,615],{"id":401,"type":402,"label":439,"file":267,"line":141},{"id":406,"type":407,"label":408,"file":267,"line":616,"wp_function":410},98,[618],{"from":401,"to":406,"sanitized":264},{"entryPoint":620,"graph":621,"unsanitizedCount":28,"severity":83},"zcf_updateFormTitle (includes\\crmcustomfunctions.php:122)",{"nodes":622,"edges":629},[623,625],{"id":401,"type":402,"label":439,"file":267,"line":624},125,{"id":406,"type":407,"label":626,"file":267,"line":627,"wp_function":628},"query() [SQLi]",128,"query",[630],{"from":401,"to":406,"sanitized":264},{"entryPoint":632,"graph":633,"unsanitizedCount":27,"severity":83},"zcf_FieldsAjaxAction (includes\\crmcustomfunctions.php:136)",{"nodes":634,"edges":663},[635,637,639,642,644,645,648,650,652,654,655,658,661],{"id":401,"type":402,"label":483,"file":267,"line":636},145,{"id":406,"type":407,"label":408,"file":267,"line":638,"wp_function":410},249,{"id":412,"type":402,"label":640,"file":267,"line":641},"$_REQUEST (x8)",147,{"id":415,"type":407,"label":442,"file":267,"line":643,"wp_function":444},267,{"id":514,"type":402,"label":439,"file":267,"line":363},{"id":518,"type":646,"label":647,"file":267,"line":363},"transform","→ zcfupdateDataeditScodeFields()",{"id":520,"type":407,"label":408,"file":303,"line":649,"wp_function":410},197,{"id":522,"type":402,"label":452,"file":267,"line":651},261,{"id":569,"type":646,"label":653,"file":267,"line":651},"→ zcfDeleteFields()",{"id":572,"type":407,"label":408,"file":303,"line":60,"wp_function":410},{"id":656,"type":402,"label":439,"file":267,"line":657},"n10",315,{"id":659,"type":646,"label":660,"file":267,"line":657},"n11","→ zcfupdateScodeFields()",{"id":662,"type":407,"label":408,"file":303,"line":466,"wp_function":410},"n12",[664,665,666,667,668,669,670,671],{"from":401,"to":406,"sanitized":266},{"from":412,"to":415,"sanitized":266},{"from":514,"to":518,"sanitized":264},{"from":518,"to":520,"sanitized":264},{"from":522,"to":569,"sanitized":264},{"from":569,"to":572,"sanitized":264},{"from":656,"to":659,"sanitized":264},{"from":659,"to":662,"sanitized":264},{"entryPoint":673,"graph":674,"unsanitizedCount":27,"severity":83},"zcf_NormalFieldAjaxAction (includes\\crmcustomfunctions.php:400)",{"nodes":675,"edges":690},[676,678,680,682,684,686,688],{"id":401,"type":402,"label":452,"file":267,"line":677},412,{"id":406,"type":407,"label":442,"file":267,"line":679,"wp_function":444},416,{"id":412,"type":402,"label":413,"file":267,"line":681},458,{"id":415,"type":407,"label":408,"file":267,"line":683,"wp_function":410},481,{"id":514,"type":402,"label":439,"file":267,"line":685},421,{"id":518,"type":646,"label":687,"file":267,"line":685},"→ zcf_updateform_title()",{"id":520,"type":407,"label":408,"file":267,"line":689,"wp_function":410},384,[691,692,693,694],{"from":401,"to":406,"sanitized":264},{"from":412,"to":415,"sanitized":264},{"from":514,"to":518,"sanitized":264},{"from":518,"to":520,"sanitized":264},{"entryPoint":696,"graph":697,"unsanitizedCount":759,"severity":83},"\u003Ccrmcustomfunctions> (includes\\crmcustomfunctions.php:0)",{"nodes":698,"edges":743},[699,701,702,704,705,706,707,708,709,710,712,713,714,715,717,719,721,723,725,727,729,731,733,736,739],{"id":401,"type":402,"label":700,"file":267,"line":141},"$_REQUEST (x6)",{"id":406,"type":407,"label":408,"file":267,"line":616,"wp_function":410},{"id":412,"type":402,"label":703,"file":267,"line":453},"$_REQUEST (x20)",{"id":415,"type":407,"label":442,"file":267,"line":455,"wp_function":444},{"id":514,"type":402,"label":439,"file":267,"line":624},{"id":518,"type":407,"label":626,"file":267,"line":627,"wp_function":628},{"id":520,"type":402,"label":413,"file":267,"line":681},{"id":522,"type":407,"label":408,"file":267,"line":683,"wp_function":410},{"id":569,"type":402,"label":483,"file":267,"line":636},{"id":572,"type":407,"label":416,"file":267,"line":711,"wp_function":418},700,{"id":656,"type":402,"label":439,"file":267,"line":363},{"id":659,"type":646,"label":647,"file":267,"line":363},{"id":662,"type":407,"label":408,"file":303,"line":649,"wp_function":410},{"id":716,"type":402,"label":452,"file":267,"line":651},"n13",{"id":718,"type":646,"label":653,"file":267,"line":651},"n14",{"id":720,"type":407,"label":408,"file":303,"line":60,"wp_function":410},"n15",{"id":722,"type":402,"label":439,"file":267,"line":657},"n16",{"id":724,"type":646,"label":660,"file":267,"line":657},"n17",{"id":726,"type":407,"label":408,"file":303,"line":466,"wp_function":410},"n18",{"id":728,"type":402,"label":439,"file":267,"line":685},"n19",{"id":730,"type":646,"label":687,"file":267,"line":685},"n20",{"id":732,"type":407,"label":408,"file":267,"line":689,"wp_function":410},"n21",{"id":734,"type":402,"label":564,"file":267,"line":735},"n22",512,{"id":737,"type":646,"label":738,"file":267,"line":735},"n23","→ zcfcreatenewRecord()",{"id":740,"type":407,"label":408,"file":741,"line":742,"wp_function":410},"n24","includes\\crmwebformfieldsfuntions.php",230,[744,745,746,747,748,749,750,751,752,753,754,755,756,757,758],{"from":401,"to":406,"sanitized":266},{"from":412,"to":415,"sanitized":266},{"from":514,"to":518,"sanitized":266},{"from":520,"to":522,"sanitized":266},{"from":569,"to":572,"sanitized":266},{"from":656,"to":659,"sanitized":264},{"from":659,"to":662,"sanitized":264},{"from":716,"to":718,"sanitized":264},{"from":718,"to":720,"sanitized":264},{"from":722,"to":724,"sanitized":264},{"from":724,"to":726,"sanitized":264},{"from":728,"to":730,"sanitized":264},{"from":730,"to":732,"sanitized":264},{"from":734,"to":737,"sanitized":264},{"from":737,"to":740,"sanitized":264},12,{"entryPoint":761,"graph":762,"unsanitizedCount":311,"severity":83},"zcfnewlead_form (includes\\crminterfunction.php:39)",{"nodes":763,"edges":777},[764,766,768,770,773,775],{"id":401,"type":402,"label":439,"file":464,"line":765},64,{"id":406,"type":646,"label":767,"file":464,"line":765},"→ zcfsynceditUploadField()",{"id":412,"type":407,"label":408,"file":293,"line":769,"wp_function":410},725,{"id":415,"type":402,"label":771,"file":464,"line":772},"$_REQUEST['shortcode']",79,{"id":514,"type":646,"label":774,"file":464,"line":772},"→ zcfDeleteShortcode()",{"id":518,"type":407,"label":626,"file":293,"line":776,"wp_function":628},826,[778,779,780,781],{"from":401,"to":406,"sanitized":264},{"from":406,"to":412,"sanitized":264},{"from":415,"to":514,"sanitized":264},{"from":514,"to":518,"sanitized":264},{"entryPoint":783,"graph":784,"unsanitizedCount":311,"severity":83},"\u003Ccrminterfunction> (includes\\crminterfunction.php:0)",{"nodes":785,"edges":794},[786,787,788,789,790,791,792,793],{"id":401,"type":402,"label":564,"file":464,"line":348},{"id":406,"type":407,"label":442,"file":464,"line":466,"wp_function":444},{"id":412,"type":402,"label":439,"file":464,"line":765},{"id":415,"type":646,"label":767,"file":464,"line":765},{"id":514,"type":407,"label":408,"file":293,"line":769,"wp_function":410},{"id":518,"type":402,"label":771,"file":464,"line":772},{"id":520,"type":646,"label":774,"file":464,"line":772},{"id":522,"type":407,"label":626,"file":293,"line":776,"wp_function":628},[795,796,797,798,799],{"from":401,"to":406,"sanitized":266},{"from":412,"to":415,"sanitized":264},{"from":415,"to":514,"sanitized":264},{"from":518,"to":520,"sanitized":264},{"from":520,"to":522,"sanitized":264},{"entryPoint":801,"graph":802,"unsanitizedCount":882,"severity":83},"\u003Ccrmshortcodefunctions> (includes\\crmshortcodefunctions.php:0)",{"nodes":803,"edges":863},[804,806,808,809,810,811,812,813,814,815,816,818,820,821,823,824,828,830,832,834,836,838,840,842,844,845,848,851,854,857,860],{"id":401,"type":402,"label":452,"file":293,"line":805},24,{"id":406,"type":407,"label":408,"file":293,"line":807,"wp_function":410},117,{"id":412,"type":402,"label":504,"file":293,"line":505},{"id":415,"type":407,"label":507,"file":293,"line":505,"wp_function":508},{"id":514,"type":402,"label":510,"file":293,"line":511},{"id":518,"type":407,"label":507,"file":293,"line":511,"wp_function":508},{"id":520,"type":402,"label":515,"file":293,"line":516},{"id":522,"type":407,"label":507,"file":293,"line":516,"wp_function":508},{"id":569,"type":402,"label":439,"file":293,"line":496},{"id":572,"type":407,"label":507,"file":293,"line":523,"wp_function":508},{"id":656,"type":402,"label":483,"file":293,"line":817},227,{"id":659,"type":407,"label":626,"file":293,"line":819,"wp_function":628},824,{"id":662,"type":402,"label":483,"file":293,"line":817},{"id":716,"type":407,"label":416,"file":293,"line":822,"wp_function":418},849,{"id":718,"type":402,"label":439,"file":293,"line":817},{"id":720,"type":407,"label":825,"file":293,"line":826,"wp_function":827},"get_row() [SQLi]",945,"get_row",{"id":722,"type":402,"label":439,"file":293,"line":829},622,{"id":724,"type":646,"label":831,"file":293,"line":829},"→ zcfformfieldsPropsettings()",{"id":726,"type":407,"label":408,"file":303,"line":833,"wp_function":410},343,{"id":728,"type":402,"label":439,"file":293,"line":835},659,{"id":730,"type":646,"label":837,"file":293,"line":835},"→ zcfupdateFieldsOrder()",{"id":732,"type":407,"label":408,"file":293,"line":839,"wp_function":410},577,{"id":734,"type":402,"label":439,"file":293,"line":841},696,{"id":737,"type":646,"label":843,"file":293,"line":841},"→ ZcfformatContactFields()",{"id":740,"type":407,"label":825,"file":293,"line":826,"wp_function":827},{"id":846,"type":402,"label":483,"file":293,"line":847},"n25",726,{"id":849,"type":646,"label":850,"file":293,"line":847},"n26","→ zcffieldsPropsettings()",{"id":852,"type":407,"label":408,"file":303,"line":853,"wp_function":410},"n27",318,{"id":855,"type":402,"label":439,"file":293,"line":856},"n28",979,{"id":858,"type":646,"label":859,"file":293,"line":856},"n29","→ ZcfcontactFormRelation()",{"id":861,"type":407,"label":416,"file":293,"line":862,"wp_function":418},"n30",984,[864,865,866,867,868,869,870,871,872,873,874,875,876,877,878,879,880,881],{"from":401,"to":406,"sanitized":264},{"from":412,"to":415,"sanitized":266},{"from":514,"to":518,"sanitized":266},{"from":520,"to":522,"sanitized":266},{"from":569,"to":572,"sanitized":266},{"from":656,"to":659,"sanitized":264},{"from":662,"to":716,"sanitized":264},{"from":718,"to":720,"sanitized":266},{"from":722,"to":724,"sanitized":264},{"from":724,"to":726,"sanitized":264},{"from":728,"to":730,"sanitized":264},{"from":730,"to":732,"sanitized":264},{"from":734,"to":737,"sanitized":264},{"from":737,"to":740,"sanitized":266},{"from":846,"to":849,"sanitized":264},{"from":849,"to":852,"sanitized":264},{"from":855,"to":858,"sanitized":264},{"from":858,"to":861,"sanitized":264},13,{"entryPoint":884,"graph":885,"unsanitizedCount":389,"severity":83},"\u003Ccrmwebformfields> (includes\\crmwebformfields.php:0)",{"nodes":886,"edges":925},[887,890,891,893,895,897,899,902,903,905,906,908,909,911,913,914,915,916,917,918,919,920,921,923],{"id":401,"type":402,"label":888,"file":354,"line":889},"$_REQUEST['onAction'] (x3)",22,{"id":406,"type":407,"label":507,"file":354,"line":889,"wp_function":508},{"id":412,"type":402,"label":892,"file":354,"line":27},"$_REQUEST (x15)",{"id":415,"type":407,"label":507,"file":354,"line":894,"wp_function":508},89,{"id":514,"type":402,"label":483,"file":354,"line":896},127,{"id":518,"type":407,"label":408,"file":354,"line":898,"wp_function":410},134,{"id":520,"type":402,"label":900,"file":354,"line":901},"$_REQUEST['module'] (x2)",216,{"id":522,"type":407,"label":408,"file":354,"line":901,"wp_function":410},{"id":569,"type":402,"label":510,"file":354,"line":904},291,{"id":572,"type":407,"label":408,"file":354,"line":904,"wp_function":410},{"id":656,"type":402,"label":510,"file":354,"line":907},470,{"id":659,"type":407,"label":825,"file":354,"line":907,"wp_function":827},{"id":662,"type":402,"label":439,"file":354,"line":910},165,{"id":716,"type":646,"label":912,"file":354,"line":910},"→ zcfformFields()",{"id":718,"type":407,"label":408,"file":293,"line":898,"wp_function":410},{"id":720,"type":402,"label":504,"file":354,"line":910},{"id":722,"type":646,"label":912,"file":354,"line":910},{"id":724,"type":407,"label":408,"file":293,"line":807,"wp_function":410},{"id":726,"type":402,"label":515,"file":354,"line":388},{"id":728,"type":646,"label":912,"file":354,"line":388},{"id":730,"type":407,"label":408,"file":293,"line":807,"wp_function":410},{"id":732,"type":402,"label":439,"file":354,"line":241},{"id":734,"type":646,"label":922,"file":354,"line":241},"→ zcfFormPropSettings()",{"id":737,"type":407,"label":408,"file":303,"line":924,"wp_function":410},396,[926,927,928,929,930,931,932,933,934,935,936,937,938,939],{"from":401,"to":406,"sanitized":266},{"from":412,"to":415,"sanitized":266},{"from":514,"to":518,"sanitized":264},{"from":520,"to":522,"sanitized":264},{"from":569,"to":572,"sanitized":264},{"from":656,"to":659,"sanitized":264},{"from":662,"to":716,"sanitized":264},{"from":716,"to":718,"sanitized":264},{"from":720,"to":722,"sanitized":264},{"from":722,"to":724,"sanitized":264},{"from":726,"to":728,"sanitized":264},{"from":728,"to":730,"sanitized":264},{"from":732,"to":734,"sanitized":264},{"from":734,"to":737,"sanitized":266},{"summary":941,"deductions":942},"The Zoho CRM Forms plugin exhibits a mixed security posture. On one hand, it demonstrates good practices by utilizing prepared statements for the vast majority of its SQL queries (99%) and properly escaping a high percentage of its output (95%). The total entry points are manageable, and importantly, no entry points were found to be completely unprotected by authentication checks. Nonce checks are also present, indicating an awareness of common WordPress security vectors.\n\nHowever, several concerning signals emerge from the static analysis. The presence of 6 'unserialize' function calls is a significant red flag, as this function is notoriously prone to object injection vulnerabilities if not handled with extreme care. Furthermore, the taint analysis reveals 13 high-severity flows, suggesting potential vulnerabilities where unsanitized input could be used in a dangerous context. While the static analysis reports no unprotected AJAX handlers, the high number of unsanitized paths in the taint analysis (18 out of 23) is concerning and could represent potential injection points if these flows are not adequately sanitized downstream.\n\nThe vulnerability history paints a picture of a plugin that has had recurring security issues. With 6 known CVEs, one of which is still unpatched and rated as high severity, this plugin has a track record of exploitable flaws, including SQL injection, missing authorization, and cross-site scripting. The most recent vulnerability in 2026 is concerning, as it suggests ongoing or recurring security problems. While the plugin has strengths in its general handling of SQL and output, the recurring nature of vulnerabilities and the presence of 'unserialize' coupled with high-severity taint flows warrant careful consideration.",[943,945,947,949,951],{"reason":944,"points":283},"Unpatched High Severity CVE",{"reason":946,"points":882},"High-severity taint flows found",{"reason":948,"points":173},"Presence of 'unserialize' function",{"reason":950,"points":389},"18 flows with unsanitized paths",{"reason":952,"points":142},"Bundled library (Select2) potential for issues","2026-03-16T18:18:53.218Z",{"wat":955,"direct":974},{"assetPaths":956,"generatorPatterns":964,"scriptPaths":965,"versionParams":966},[957,958,959,960,961,962,963],"\u002Fwp-content\u002Fplugins\u002Fzoho-crm-forms\u002Fassets\u002Fcss\u002Fselect2.min.css","\u002Fwp-content\u002Fplugins\u002Fzoho-crm-forms\u002Fassets\u002Fjs\u002Fselect2.full.min.js","\u002Fwp-content\u002Fplugins\u002Fzoho-crm-forms\u002Fassets\u002Fjs\u002Fzcf.js","\u002Fwp-content\u002Fplugins\u002Fzoho-crm-forms\u002Fassets\u002Fjs\u002Fcrmforms-builder.js","\u002Fwp-content\u002Fplugins\u002Fzoho-crm-forms\u002Fassets\u002Fjs\u002Fcrmforms-generator.js","\u002Fwp-content\u002Fplugins\u002Fzoho-crm-forms\u002Fassets\u002Fjs\u002Fcrmforms-helper.js","\u002Fwp-content\u002Fplugins\u002Fzoho-crm-forms\u002Fassets\u002Fjs\u002Fcrmforms-validate.js",[],[958,959,960,961,962,963],[967,968,969,970,971,972,973],"zoho-crm-forms\u002Fassets\u002Fcss\u002Fselect2.min.css?ver=","zoho-crm-forms\u002Fassets\u002Fjs\u002Fselect2.full.min.js?ver=","zoho-crm-forms\u002Fassets\u002Fjs\u002Fzcf.js?ver=","zoho-crm-forms\u002Fassets\u002Fjs\u002Fcrmforms-builder.js?ver=","zoho-crm-forms\u002Fassets\u002Fjs\u002Fcrmforms-generator.js?ver=","zoho-crm-forms\u002Fassets\u002Fjs\u002Fcrmforms-helper.js?ver=","zoho-crm-forms\u002Fassets\u002Fjs\u002Fcrmforms-validate.js?ver=",{"cssClasses":975,"htmlComments":978,"htmlAttributes":992,"restEndpoints":1010,"jsGlobals":1013,"shortcodeOutput":1019},[976,977],"zcf-select2-container","zcf-select2-dropdown",[979,980,981,982,983,984,985,986,987,988,989,990,991],"\u003C!-- Zoho CRM Lead Magnet -->","\u003C!-- Zoho crm forms -->","\u003C!-- Zoho CRM Forms -->","\u003C!-- Zoho crmforms-builder -->","\u003C!-- Zoho formsettings-builder -->","\u003C!-- Zoho lb-crmconfig -->","\u003C!-- Zoho formsubmit-logs -->","\u003C!-- Zoho crm-authentications -->","\u003C!-- Zoho crmforms-authendication -->","\u003C!-- Zoho create-thirdpartyform-builder -->","\u003C!-- Zoho create-leadform-builder -->","\u003C!-- Zoho create-contactform-builder -->","\u003C!-- Zoho zoho-crm-form-builder -->",[993,994,995,996,997,998,999,1000,1001,1002,1003,1004,1005,1006,1007,1008,1009],"data-toggle","data-placement","data-id","data-label","data-value","order-pos","data-status","data-width","data-height","data-rtl","data-show-thumbnails","data-background-size","data-blur-background","data-background-color","data-thumbnail-background-color","data-alt","data-src",[1011,1012],"\u002Fwp-json\u002Fzcf\u002Fv1\u002Fforms","\u002Fwp-json\u002Fzcf\u002Fv1\u002Fsettings",[1014,1015,1016,1017,1018],"zcf_ajax_url","zcf_nonce","zcf_settings","zcf_forms","zcf_generator_settings",[1020],"[zoho-crm-form]"]