This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
OffSequence
offseq.bsky.social
did:plc:t5t6qep2vfipbi7f54demwev
PHP Object Injection in WS Form LITE ≤1.10.80 (CVE-2026-4703, CRITICAL). RCE possible if a POP chain is present in another plugin/theme. Audit your WordPress setup, remove risky components, and monitor for patches. https://radar.offseq.com/threat/the-ws-form-lite-drag-drop-contact-form-builder-pl...
https://radar.offseq.com/threat/the-ws-form-lite-drag-drop-contact-form-builder-plugin-for-wordpress-is-vulnerable-to-php-object-f688cffee1daa479
2026-08-23T01:30:28.774Z