Constant Contact Forms [constant-contact-forms] < 2.0.0
unknown
[en] Missing Authorization vulnerability in Constant Contact Constant Contact Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Constant Contact Forms: from n/a through 2.0.3.
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
- Disclosed:
- Dec 13, 2024
CVE-2023-34387 on NVD →
Constant Contact Forms [constant-contact-forms] < 2.4.3
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Constant Contact Constant Contact Forms.This issue affects Constant Contact Forms: from n/a through 2.4.2.
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.3
- Disclosed:
- Jan 8, 2024
CVE-2023-52208 on NVD →
Constant Contact Forms <= 2.4.2 - Information Disclosure via Log Files
medium
The Constant Contact Forms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.2. This makes it possible for unauthenticated attackers to extract sensitive data from log files.
- CVSS:
- 5.3
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.3
- Disclosed:
- Jan 3, 2024
CVE-2023-52208 on NVD →
Constant Contact Forms <= 2.0.2 - Missing Authorization via constant_contact_privacy_ajax_handler
medium
The Constant Contact Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the constant_contact_privacy_ajax_handler function in versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level access and above,...
- CVSS:
- 4.3
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.3
- Disclosed:
- Jun 15, 2023
Constant Contact Forms [constant-contact-forms] < 2.0.3
unknown
The Constant Contact Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the constant_contact_privacy_ajax_handler function in versions up to, and including, 2.0.2. This makes it possible for authenticated attackers, with subscriber-level access and above,...
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.3
- Disclosed:
- Jun 15, 2023
Constant Contact Forms <= 1.14.0 - Missing Authorization via constant_contact_optin_ajax_handler
medium
The Constant Contact Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the constant_contact_optin_ajax_handler function in versions up to, and including, 1.14.0. This makes it possible for authenticated attackers, with subscriber-level access and above, t...
- CVSS:
- 4.3
- Affected:
- up to 1.14.0
- Fixed in:
- 2.0.0
- Disclosed:
- Jun 3, 2023
CVE-2023-34387 on NVD →
Constant Contact Forms [constant-contact-forms] < 1.8.8
unknown
[en] Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-privileged user (Editor+) to inject arbitrary JavaScript code or HTML in posts where the malicious form is embed.
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Mar 18, 2021
CVE-2021-24134 on NVD →
Constant Contact Forms <= 1.8.7 Editor+ Stored Cross-Site Scripting
medium
Unvalidated input and lack of output encoding in the Constant Contact Forms WordPress plugin, versions before 1.8.8, lead to multiple Stored Cross-Site Scripting vulnerabilities, which allowed high-privileged user (Editor+) to inject arbitrary JavaScript code or HTML in posts where the malicious form is embed.
- CVSS:
- 5.5
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Sep 6, 2020
CVE-2021-24134 on NVD →
Constant Contact Forms [constant-contact-forms] < 1.8.8
unknown
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities found by Nguyen Anh Tien (SunCSR) in WordPress Constant Contact Forms plugin (versions <= 1.8.7).
- Affected:
- up to 1.8.8
- Fixed in:
- 1.8.8
- Disclosed:
- Sep 6, 2020
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database