Contact Form X
Displays a user-friendly contact form that your visitors will love. CFX: Contact form reinvented. Fast and friendly. Fresh and clean. Awesome for everyone 🙂 Overview Install, activate, and then display the form anywhere, using the widget, shortcode, or template tag. Here is an overview of Contact Form X: Easy to use Simple and secure ADA and WCAG compliant Lightweight and super fast Provides multiple form styles Customize just about everything Display the contact form anywhere Add Checkbox, Radio, and Select fields Customize the order of all form fields Send email to multiple recipients Complete documentation via Help tab Excellent free plugin support 😎 “The famous spam filter SpamAssassin” scores CFX = zero spam! For more details, check out the “Screenshots” section, below. Form Fields Easily choose which fields to display in the form. Each field may be set as required, optional, or disabled. Choose from these fields: Name Website Email Subject Custom Field 1 (can be dropdown, checkbox, radio, text, or phone number) Custom Field 2 (can be dropdown, checkbox, radio, text, or phone number) Custom Field 3 (can be dropdown, checkbox, radio, text, or phone number) Challenge Question Message Google reCaptcha (v2 or v3 Invisible) Cloudflare Turnstile (Invisible Captcha) Carbon Copy Agree to Terms You can change the order of these fields and customize their labels and placeholders, everything is super flexible. For a live demo of Contact Form X, visit my support page at Plugin Planet, and also my contact page at Perishable Press. Feel free to send a test email to see how it works, I won’t mind 😉 Also check out CFX in the “Screenshots” section (below) for a better idea of how the default form is styled out of the box. Geeky Stuff Lots of goodness for the geeks among us: Built with WordPress APIs Ajax-powered form submission Remembers all form data on error Cloudflare Turnstile (Invisible Captcha) Google reCaptcha (v2 or v3 Invisible) Drag/drop ordering of all form fields View your email messages on the WP Dashboard Option to enable/disable storing of email data in database Display form via widget, shortcode, or template tag Five CSS themes: Default, Classic, Micro, Synthetic, Dark Optionally disable all plugin styles and use your own CSS Optionally collect user data like IP, host, and referrer Works perfectly with or without Gutenberg Block Editor Focused on performance, security, and usability Include extra form and user info with each message Customize the form’s success and error messages Provides plenty of useful hooks for developers Targeted loading of CSS and JavaScript assets One-click remove email data from database One-click restore default options Translation ready Contact Form X is a fresh new, lighter alternative to the heavier contact forms out there. CFX is lightweight yet fully featured. As they say, “everything you want, nothing you don’t”. Privacy To help protect user privacy, Contact Form X provides the following features: Agree to terms checkbox, customizable Choose which fields to include with the form Option to disable collection of user IP address and other data Note: this plugin uses cookies to enhance form functionality Basically, this plugin enables visitors to send a message via contact form. Any information the user enters into the form will be sent directly to the recipient(s) according to plugin settings. When enabled in the plugin settings, details about each sent message will be stored in the WordPress database. Visit the “Advanced” plugin settings to control and/or disable this and other data-collection features. Note: CFX provides an option to enable Google reCaptcha, which is provided by Google as a third-party service. For details on privacy and more, please refer to official documentation for Google reCaptcha. Contact Form X is developed and maintained by Jeff Starr, 15-year WordPress developer and book author. Support development I develop and maintain this free plugin with love for the WordPress community. To show support, you can make a donation or purchase one of my books: The Tao of WordPress Digging into WordPress .htaccess made easy WordPress Themes In Depth Wizard’s SQL Recipes for WordPress And/or purchase one of my premium WordPress plugins: BBQ Pro – Blazing fast WordPress firewall Blackhole Pro – Automatically block bad bots Banhammer Pro – Monitor traffic and ban the bad guys GA Google Analytics Pro – Connect WordPress to Google Analytics Head Meta Pro – Ultimate Meta Tags for WordPress REST Pro Tools – Awesome tools for managing the WP REST API Simple Ajax Chat Pro – Unlimited chat rooms USP Pro – Unlimited front-end forms Links, tweets and likes also appreciated. Thanks! 🙂
Top keywords
- form24×3.20%
- wordpress12×1.60%
- contact11×1.47%
- contact form9×1.20%
- fields8×1.07%
- pro8×1.07%
- google7×0.93%
- email6×0.80%
- cfx5×0.67%
- checkbox5×0.67%
- data5×0.67%
- user5×0.67%
Send From
I have issues with my hosting service not allowing me to easily set the ‘From line’ for my server email. Whenever a new user signs up they see
[email protected] even though they should see
[email protected]. Before Send From you would be required to modify your installation of WordPress just about every time you do an update. No longer! With Send From, you simply go into your admin panel and set what the end user will see on their emails from line. Support Questions If there are any issues that crop up, I will be happy to take a look at solving them. However, due to many factors, I can’t offer active support for the plugin. Security CVE: CVE-2025-46469 – Cross-site scripting (Stored XSS) in plugin settings. Summary: A stored XSS issue was reported in older versions of this plugin where un-sanitized input saved in plugin options could later be rendered into the admin interface without proper escaping. The repository has been updated to sanitize incoming option values and escape output when rendering form fields. The plugin also validates the test-send email address. Mitigation applied in this repository: – Sanitize email values with WordPress’ sanitize_email() before saving. – Sanitize name fields with sanitize_text_field() before saving. – Escape values when printed into HTML attributes using esc_attr(). – Validate test-send addresses with is_email() and refuse to save invalid addresses.
Top keywords
- email5×2.16%
- sanitize5×2.16%
- see3×1.30%
- user3×1.30%
- values3×1.30%
- addresses2×0.87%
- admin2×0.87%
- com