Resources /
WordPress Plugins /
FormLayer
PLUGIN SECURITY
Is FormLayer safe?
Build fast and powerful contact forms in WordPress with an intuitive drag-and-drop builder packed with smart features.
What this plugin does
- Slug:
formlayer
- Author: Softaculous
- 80000+ active installs
- 60334 all-time downloads
- On WordPress.org since 2026-05-26
contact formcustom formformsforms builder
Maintenance status
- Last updated: 2026-07-02 8:36am GMT
- Tested up to WordPress: 7.0.2
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
1 known CVE on file for FormLayer.
Reported between 2026 and 2026.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-59519
|
FormLayer [formlayer] < 1.0.7 |
Insertion of Sensitive Information Into Sent Data |
Medium
5.3
|
< 1.0.7
|
1.0.7 |
2026-07-05 |
—
|
CVE-2026-59519
<p>WordPress FormLayer Plugin <= 1.0.6 is vulnerable to Sensitive Data Exposure</p><p>Software: FormLayer</p><p>Link: https://wordpress.org/support/plugin/formlayer/</p><p>Fixed in version 1.0.7 </p><p>Affected Version <= 1.0.6</p><p>CVE: CVE-2026-59519</p>
Source:
Patchstack
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.