VendorsCodePeoplecp_contact_form_with_paypalall versions
Vulnerabilities

CodePeople CP Contact Form with PayPal

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2015-9233
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php.
Published 2017-09-29 · Modified
8.8EPSS 0.010
CVE-2023-27460
WordPress CP Contact Form with PayPal plugin <= 1.3.34 - Missing Authorization Leading To Feedback Submission vulnerability
Published 2024-06-03 · Analyzed
8.8EPSS 0.004
CVE-2019-14784
The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.
Published 2019-08-15 · Modified
6.1EPSS 0.009
CVE-2019-14785
The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter.
Published 2019-08-09 · Modified
5.4EPSS 0.008