CVE-2026-32532

WordPress Contact Form & Lead Form Elementor Builder plugin <= 2.0.1 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder lead-form-builder allows Stored XSS.This issue affects Contact Form & Lead Form Elementor Builder: from n/a through <= 2.0.1.


We have discovered 751 live websites that are affected by CVE-2026-32532.

Run a Free Instant Scan




Affected Software

Product  Lead Form Builder
Category Wordpress Plugins
Vulnerable Domains751 live websites (100% of Lead Form Builder install base)
Vulnerable Versions
  • from 0 through 2.0.1
Vulnerable Versions Count35 versions ( 97% of all versions)



Details

  • Published - Mar 25, 2026
  • Updated - Apr 29, 2026

Credits

  • daroo | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-32532
United States232 websites



Germany53 websites
France48 websites
GB31 websites
Netherlands26 websites
Poland26 websites
Russia23 websites
South Africa21 websites
India21 websites
Austria20 websites

Website Distribution by TLD

Number of websites using CVE-2026-32532
.com301 websites
.nl28 websites
.de28 websites
.org26 websites
.fr22 websites
.at21 websites
.ru21 websites
.pl19 websites
.net15 websites
.co.uk14 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-32532

Top websites that are affected by CVE-2026-32532. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.info United States***,***
*******.be France*,***,***
*********.ir Iran*,***,***
***********.tn Tunisia*,***,***
********.com India*,***,***
*******.**.uk GB*,***,***
*******.com United States*,***,***
*********.com Germany*,***,***
************.com United States*,***,***
**.******.com United States*,***,***
See full domain list

FAQ

A total of 751 websites have been identified as vulnerable to CVE-2026-32532, based on global website indexing conducted by WebTechSurvey.
The Lead Form Builder is affected by the CVE-2026-32532 vulnerability.
Lead Form Builder versions up to and including 2.0.1 are vulnerable to CVE-2026-32532.