WordPress Plugin weForms-Easy Drag Drop Contact Form Builder For WordPress Supply Chain Attack Polyfill.io - Vulnerability Database

WordPress Plugin weForms-Easy Drag Drop Contact Form Builder For WordPress Supply Chain Attack Polyfill.io

Critical
Reference: No Reference
Title: WordPress Plugin weForms-Easy Drag Drop Contact Form Builder For WordPress Supply Chain Attack Polyfill.io
Overview:

WordPress Plugin weForms-Easy Drag Drop Contact Form Builder For WordPress is prone to a supply chain attack because of the Polyfill JavaScript library used. The ownership of the library was taken over by malicious threat actors that used the service to redirect victims to malicious websites. WordPress Plugin weForms-Easy Drag Drop Contact Form Builder For WordPress version 1.6.23 is affected prior versions may also be affected.