Contact Form Email <= 1.3.63 - Missing Authorization
medium
The Contact Form Email plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.63. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.3.63
- Fixed in:
- 1.3.64
- Disclosed:
- Mar 23, 2026
CVE-2026-32483 on NVD →
Contact Form Email [contact-form-to-email] <= 1.3.60 (unfixed)
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through <= 1.3.60.
- Affected:
- up to 1.3.60
- Fix:
- No patched version reported
- Disclosed:
- Dec 18, 2025
CVE-2025-10019 on NVD →
Contact Form Email <= 1.3.60 - Unauthenticated Insecure Direct Object Reference
medium
The Contact Form Email plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.60 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.3.60
- Fixed in:
- 1.3.61
- Disclosed:
- Dec 1, 2025
CVE-2025-10019 on NVD →
Contact Form Email <= 1.3.58 - Missing Authorization
medium
The Contact Form Email plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.58. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.3.58
- Fixed in:
- 1.3.59
- Disclosed:
- Nov 15, 2025
CVE-2025-64369 on NVD →
Contact Form Email [contact-form-to-email] < 1.3.59
unknown
[en] Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through <= 1.3.58.
- Affected:
- up to 1.3.59
- Fixed in:
- 1.3.59
- Disclosed:
- Nov 13, 2025
CVE-2025-64369 on NVD →
Contact Form Email <= 1.3.52 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Contact Form Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.52 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in...
- CVSS:
- 4.4
- Affected:
- up to 1.3.52
- Fixed in:
- 1.3.53
- Disclosed:
- Jan 24, 2025
CVE-2025-24727 on NVD →
Contact Form Email [contact-form-to-email] < 1.3.53
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Contact Form Email allows Stored XSS. This issue affects Contact Form Email: from n/a through 1.3.52.
- Affected:
- up to 1.3.53
- Fixed in:
- 1.3.53
- Disclosed:
- Jan 24, 2025
CVE-2025-24727 on NVD →
Contact Form Email [contact-form-to-email] < 1.3.42
unknown
[en] Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Contact Form Email allows Functionality Bypass.This issue affects Contact Form Email: from n/a through 1.3.41.
- Affected:
- up to 1.3.42
- Fixed in:
- 1.3.42
- Disclosed:
- Jun 4, 2024
CVE-2023-48318 on NVD →
Contact Form Email [contact-form-to-email] < 1.3.32
unknown
[en] Missing Authorization vulnerability in CodePeople Contact Form Email allows Functionality Misuse.This issue affects Contact Form Email: from n/a through 1.3.31.
- Affected:
- up to 1.3.32
- Fixed in:
- 1.3.32
- Disclosed:
- Jun 4, 2024
CVE-2023-28494 on NVD →
Contact Form Email [contact-form-to-email] < 1.3.45
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodePeople Contact Form Email.This issue affects Contact Form Email: from n/a through 1.3.44.
- Affected:
- up to 1.3.45
- Fixed in:
- 1.3.45
- Disclosed:
- Apr 10, 2024
CVE-2024-31302 on NVD →
Contact Form Email <= 1.3.44 - Unauthenticated Sensitive Information Exposure
medium
The Contact Form Email plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.44 via log files. This makes it possible for unauthenticated attackers to extract sensitive data from log files.
- CVSS:
- 5.3
- Affected:
- up to 1.3.44
- Fixed in:
- 1.3.45
- Disclosed:
- Apr 5, 2024
CVE-2024-31302 on NVD →
Contact Form Email [contact-form-to-email] < 1.3.44
unknown
[en] The Contact Form Email WordPress plugin before 1.3.44 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 1.3.44
- Fixed in:
- 1.3.44
- Disclosed:
- Dec 11, 2023
CVE-2023-5955 on NVD →
Contact Form Email <= 1.3.41 - Captcha Bypass
medium
The Contact Form Email plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 1.3.41. This makes it possible for unauthenticated attackers to bypass the Captcha Verification.
- CVSS:
- 5.3
- Affected:
- up to 1.3.41
- Fixed in:
- 1.3.42
- Disclosed:
- Nov 23, 2023
CVE-2023-48318 on NVD →
Contact Form Email <= 1.3.43 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Contact Form Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.3.43 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inje...
- CVSS:
- 4.4
- Affected:
- up to 1.3.43
- Fixed in:
- 1.3.44
- Disclosed:
- Nov 14, 2023
CVE-2023-5955 on NVD →
Contact Form Email [contact-form-to-email] < 1.3.38
unknown
[en] The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability.
- Affected:
- up to 1.3.38
- Fixed in:
- 1.3.38
- Disclosed:
- Jun 12, 2023
CVE-2023-2718 on NVD →
Contact Form Email <= 1.3.37 - Unauthenticated Stored Cross-Site Scripting
high
The Contact Form Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Message' field in versions up to, and including, 1.3.37 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex...
- CVSS:
- 7.2
- Affected:
- up to 1.3.37
- Fixed in:
- 1.3.38
- Disclosed:
- May 16, 2023
CVE-2023-2718 on NVD →
Contact Form Email <= 1.3.31 - Cross-Site Request Forgery to Feedback Submission
medium
The Contact Form Email plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.31. This is due to missing or incorrect nonce validation on the cpcfte_feedback function. This makes it possible for unauthenticated attackers to submit plugin feedback via a forged request gran...
- CVSS:
- 4.3
- Affected:
- up to 1.3.31
- Fixed in:
- 1.3.32
- Disclosed:
- Mar 21, 2023
Contact Form Email [contact-form-to-email] < 1.3.32
unknown
The Contact Form Email plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.31. This is due to missing or incorrect nonce validation on the cpcfte_feedback function. This makes it possible for unauthenticated attackers to submit plugin feedback via a forged request gran...
- Affected:
- up to 1.3.32
- Fixed in:
- 1.3.32
- Disclosed:
- Mar 21, 2023
Contact Form Email <= 1.3.31 - Missing Authorization to Feedback Submission
medium
The Contact Form Email for WordPress is vulnerable to unauthorized feedback submission due to a missing capability check on the cpcfte_feedback function in versions up to, and including, 1.3.31. This makes it possible for subscriber-level attackers to submit plugin feedback on the site owner's behalf.
- CVSS:
- 4.3
- Affected:
- up to 1.3.31
- Fixed in:
- 1.3.32
- Disclosed:
- Mar 16, 2023
CVE-2023-28494 on NVD →
Contact Form Email [contact-form-to-email] < 1.3.25
unknown
[en] The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the name parameter found in the ~/trunk/cp-admin-int-list.inc.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up t...
- Affected:
- up to 1.3.25
- Fixed in:
- 1.3.25
- Disclosed:
- Nov 17, 2021
CVE-2021-42361 on NVD →
Contact Form Email <= 1.3.24 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the name parameter found in the ~/trunk/cp-admin-int-list.inc.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and...
- CVSS:
- 4.8
- Affected:
- up to 1.3.24
- Fixed in:
- 1.3.25
- Disclosed:
- Nov 11, 2021
CVE-2021-42361 on NVD →
Contact Form Email [contact-form-to-email] < 1.2.66
unknown
[en] The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
- Affected:
- up to 1.2.66
- Fixed in:
- 1.2.66
- Disclosed:
- Aug 13, 2019
CVE-2018-20963 on NVD →
Contact Form Email [contact-form-to-email] < 1.2.66
unknown
[en] The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
- Affected:
- up to 1.2.66
- Fixed in:
- 1.2.66
- Disclosed:
- Aug 13, 2019
CVE-2018-20964 on NVD →
Contact Form Email <= 1.2.65 - Cross-Site Request Forgery
high
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
- CVSS:
- 8.8
- Affected:
- up to 1.2.65
- Fixed in:
- 1.2.66
- Disclosed:
- Aug 12, 2019
CVE-2018-20964 on NVD →
Contact Form Email <= 1.2.65 - Cross-Site Scripting
medium
The contact-form-to-email plugin before 1.2.66 for WordPress has XSS.
- CVSS:
- 6.1
- Affected:
- up to 1.2.65
- Fixed in:
- 1.2.66
- Disclosed:
- Aug 12, 2019
CVE-2018-20963 on NVD →
Contact Form Email [contact-form-to-email] < 1.2.66
unknown
[en] The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area."
- Affected:
- up to 1.2.66
- Fixed in:
- 1.2.66
- Disclosed:
- Mar 10, 2019
CVE-2019-9646 on NVD →
Contact Form Email <= 1.2.65 - Reflected Cross-Site Scripting
medium
The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area."
- CVSS:
- 6.1
- Affected:
- up to 1.2.66
- Fixed in:
- 1.2.66
- Disclosed:
- Feb 5, 2019
CVE-2019-9646 on NVD →
Contact Form Email < 1.1.48 - Reflected Cross-Site Scripting
high
The Contact Form Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cal’ parameter in versions before 1.1.48 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- CVSS:
- 7.1
- Affected:
- up to 1.1.48
- Fixed in:
- 1.1.48
- Disclosed:
- Jul 24, 2016
Contact Form Email [contact-form-to-email] < 1.1.48
unknown
Because of this vulnerability, attackers can inject malicious JavaScript code into the application.
Update the plugin.
- Affected:
- up to 1.1.48
- Fixed in:
- 1.1.48
- Disclosed:
- Jul 24, 2016
Contact Form Email [contact-form-to-email] < 1.1.48
unknown
The Contact Form Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘cal’ parameter in versions before 1.1.48 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- Affected:
- up to 1.1.48
- Fixed in:
- 1.1.48
- Disclosed:
- Jul 24, 2016
Contact Form Email <= 1.3.11 - Cross-Site Request Forgery to Cross-Site Scripting
high
The Contact Form Email plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.11. This is due to missing nonce validation on the 'cp_cfte_rep_enable' action. This makes it possible for unauthenticated attackers to modify plugin settings and inject malicious JavaScript via...
- CVSS:
- 8.8
- Affected:
- up to 1.3.12
- Fixed in:
- 1.3.12
- Disclosed:
- May 13, 2015
Contact Form Email [contact-form-to-email] < 1.3.12
unknown
The Contact Form Email plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.11. This is due to missing nonce validation on the 'cp_cfte_rep_enable' action. This makes it possible for unauthenticated attackers to modify plugin settings and inject malicious JavaScript via...
- Affected:
- up to 1.3.12
- Fixed in:
- 1.3.12
- Disclosed:
- May 13, 2015
Contact Form Email [contact-form-to-email] < 1.1.5
unknown
This plugin is prone to a cross site scripting and cross site request forgery vulnerabilities.
Upgrade this plugin.
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.5
- Disclosed:
- May 13, 2015
Contact Form Email [contact-form-to-email] < 1.1.5
unknown
This plugin is prone to a cross site scripting and cross site request forgery vulnerabilities.
Upgrade this plugin.
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.5
- Disclosed:
- May 13, 2015
Contact Form Email < 1.0.1 - Cross-Site Scripting
high
The Contact Form Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions before 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a...
- CVSS:
- 7.2
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.1
- Disclosed:
- Nov 22, 2014
Contact Form Email [contact-form-to-email] < 1.0.1
unknown
The Contact Form Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions before 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a...
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.1
- Disclosed:
- Nov 22, 2014
Contact Form Email [contact-form-to-email] < 1.1.5
unknown
- Affected:
- up to 1.1.5
- Fixed in:
- 1.1.5
Contact Form Email [contact-form-to-email] < 1.1.48
unknown
The Contact Form Email WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.1.48
- Fixed in:
- 1.1.48