VendorsCodePeoplecontact_form_emailall versions
Vulnerabilities

CodePeople Contact Form Email

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2018-20964
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
Published 2019-08-13 · Modified
8.8EPSS 0.007
CVE-2023-48318
WordPress Contact Form Email plugin <= 1.3.41 - Captcha Bypass vulnerability
Published 2024-06-04 · Analyzed
6.5EPSS 0.003
CVE-2019-9646
The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area."
Published 2019-03-10 · Modified
6.1EPSS 0.014
CVE-2018-20963
The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
Published 2019-08-13 · Modified
6.1EPSS 0.009
CVE-2023-5955
Contact Form Email < 1.3.44 - Editor+ Stored Cross-Site Scripting
Published 2023-12-11 · Modified
6.1EPSS 0.005
CVE-2025-24727
WordPress Contact Form to Email Plugin <= 1.3.52 - Cross Site Scripting (XSS) vulnerability
Published 2025-01-24 · Modified
5.9EPSS 0.003
CVE-2023-2718
Contact Form Email < 1.3.38 - Unauthenticated Stored Cross-Site Scripting
Published 2023-06-12 · Modified
5.4EPSS 0.005
CVE-2024-31302
WordPress Contact Form Email plugin <= 1.3.44 - Sensitive Data Exposure vulnerability
Published 2024-04-10 · Modified
5.3EPSS 0.005
CVE-2021-42361
Contact Form Email <= 1.3.24 Authenticated Stored Cross-Site Scripting
Published 2021-11-17 · Modified
4.8EPSS 0.006
CVE-2023-28494
WordPress Contact Form Email plugin <= 1.3.31 - Missing Authorization Leading To Feedback Submission Vulnerability
Published 2024-06-04 · Analyzed
4.3EPSS 0.003