Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Security & Risk Analysis

wordpress.org/plugins/zoho-forms

Try Zoho Forms, the best WordPress contact form plugin! Create contact, payment & custom forms with a drag and drop builder. Get started for free!

10K active installs v4.0.4 PHP + WP 2.8+ Updated Aug 8, 2025
contact-formcustom-formform-builderform-pluginforms
98
A · Safe
CVEs total3
Unpatched0
Last CVESep 30, 2024
Safety Verdict

Is Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Safe to Use in 2026?

Generally Safe

Score 98/100

Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

3 known CVEsLast CVE: Sep 30, 2024Updated 9mo ago
Risk Assessment

The "zoho-forms" v4.0.4 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no direct SQL injection vulnerabilities due to the use of prepared statements and a limited attack surface with no unprotected entry points identified. The absence of dangerous functions, file operations, and external HTTP requests is also commendable. However, the plugin's vulnerability history is a significant concern, with three previously disclosed medium-severity vulnerabilities, primarily related to Cross-Site Scripting (XSS). The fact that the last known vulnerability was very recent (September 30, 2024) and that there are currently no unpatched CVEs suggests that while vulnerabilities have been addressed, the plugin has a history of introducing such issues, requiring diligent patching.

While the current static analysis doesn't reveal active, exploitable vulnerabilities in this specific version, the pattern of past XSS vulnerabilities indicates a potential weakness in output escaping or input sanitization that could be re-introduced in future updates or might still be present in subtle ways not caught by the static analysis tools. The unescaped output rate of 25% (3 out of 12 outputs) is a point of concern, as even a single unescaped output can lead to XSS if user-supplied data is involved. The presence of the bundled TinyMCE library also warrants attention, as outdated versions of bundled libraries can introduce security risks. Despite a clean taint analysis in this version, the historical pattern and minor output escaping issues necessitate caution.

Key Concerns

  • History of 3 medium severity CVEs
  • 25% of outputs are not properly escaped
  • Bundled library (TinyMCE) can pose risk
Vulnerabilities
3 published

Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Security Vulnerabilities

CVEs by Year

2 CVEs in 2023
2023
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2024-47633medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Zoho Forms <= 4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 30, 2024 Patched in 4.0.1 (11d)
CVE-2023-50891medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Zoho Forms <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Dec 26, 2023 Patched in 3.0.2 (28d)
CVE-2023-0169medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Zoho Forms <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 23, 2023 Patched in 3.0.1 (365d)
Version History

Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

75% escaped12 total outputs
Attack Surface

Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[zohoForms] zohoForms.php:14
WordPress Hooks 4
actioninitzohoForms.php:119
filtermce_external_pluginszohoForms.php:125
filtermce_buttonszohoForms.php:126
actionenqueue_block_editor_assetszohoForms.php:160
Maintenance & Trust

Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 8, 2025
PHP min version
Downloads150K

Community Trust

Rating54/100
Number of ratings14
Active installs10K
Developer Profile

Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Developer Profile

zohosalesiq

6 plugins · 43K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
487 days
View full developer profile
Detection Fingerprints

How We Detect Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zoho-forms/zohoforms-block.js/wp-content/plugins/zoho-forms/tinymce/zforms_editor_plugin.js/wp-content/plugins/zoho-forms/zohoforms-block.css/wp-content/plugins/zoho-forms/tinymce/zFormsIcon.png
Script Paths
/wp-content/plugins/zoho-forms/tinymce/zforms_editor_plugin.js

HTML / DOM Fingerprints

CSS Classes
zf-WpPopupContainerzf-WpMainWrapzf-WpFormPermaWrapzf-WpEmbeddedWrapzf-EmbedInnerzf-WpEmbeddedHeadzf-WpEmbeddedContainerembeddedPublicLink+1 more
Data Attributes
id="zf_embedCatogory"id="zf_tiny_homeDiv"id="permaLinkDiv"id="permaContainer"id="permalink"
JS Globals
zohoFormsBlockzforms_dailog.js
Shortcode Output
[zohoForms src="[zohoForms src='<iframe height=<div id="zf_div_
FAQ

Frequently Asked Questions about Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More