plugin

Constant Contact Forms Vulnerabilities

9 known security issues reported for the Constant Contact Forms WordPress plugin. Most recent disclosed Dec 13, 2024.

4 medium

Running Constant Contact Forms on your site? Check whether your installed version is affected.

Scan your site free

Constant Contact Forms [constant-contact-forms] < 2.0.0

unknown

[en] Missing Authorization vulnerability in Constant Contact Constant Contact Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Constant Contact Forms: from n/a through 2.0.3.

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Dec 13, 2024

CVE-2023-34387 on NVD →

Constant Contact Forms [constant-contact-forms] < 2.4.3

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Constant Contact Constant Contact Forms.This issue affects Constant Contact Forms: from n/a through 2.4.2.

Affected:
up to 2.4.3
Fixed in:
2.4.3
Disclosed:
Jan 8, 2024

CVE-2023-52208 on NVD →

Constant Contact Forms <= 2.4.2 - Information Disclosure via Log Files

medium

The Constant Contact Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2. This makes it possible for unauthenticated attackers to extract sensitive data from log files.

CVSS:
5.3
Affected:
up to 2.4.2
Fixed in:
2.4.3
Disclosed:
Jan 3, 2024

CVE-2023-52208 on NVD →

Constant Contact Forms <= 2.0.2 - Missing Authorization via constant_contact_privacy_ajax_handler

medium

The Constant Contact Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the constant_contact_privacy_ajax_handler function in versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level access and above,...

CVSS:
4.3
Affected:
up to 2.0.2
Fixed in:
2.0.3
Disclosed:
Jun 15, 2023

Constant Contact Forms [constant-contact-forms] < 2.0.3

unknown

The Constant Contact Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the constant_contact_privacy_ajax_handler function in versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level access and above,...

Affected:
up to 2.0.3
Fixed in:
2.0.3
Disclosed:
Jun 15, 2023

Constant Contact Forms <= 1.14.0 - Missing Authorization via constant_contact_optin_ajax_handler

medium

The Constant Contact Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the constant_contact_optin_ajax_handler function in versions up to, and including, 1.14.0. This makes it possible for authenticated attackers, with subscriber-level access and above, t...

CVSS:
4.3
Affected:
up to 1.14.0
Fixed in:
2.0.0
Disclosed:
Jun 3, 2023

CVE-2023-34387 on NVD →

Constant Contact Forms [constant-contact-forms] < 1.8.8

unknown

[en] Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-privileged user (Editor+) to inject arbitrary JavaScript code or HTML in posts where the malicious form is embed.

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Mar 18, 2021

CVE-2021-24134 on NVD →

Constant Contact Forms <= 1.8.7 Editor+ Stored Cross-Site Scripting

medium

Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-privileged user (Editor+) to inject arbitrary JavaScript code or HTML in posts where the malicious form is embed.

CVSS:
5.5
Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Sep 6, 2020

CVE-2021-24134 on NVD →

Constant Contact Forms [constant-contact-forms] < 1.8.8

unknown

Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities found by Nguyen Anh Tien (SunCSR) in WordPress Constant Contact Forms plugin (versions <= 1.8.7).

Affected:
up to 1.8.8
Fixed in:
1.8.8
Disclosed:
Sep 6, 2020

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database