Contact Us page - Contact people LITE <= 3.7.4 - Authenticated (Contributor+) SQL Injection
medium
The Contact Us page - Contact people LITE plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contri...
- CVSS:
- 6.5
- Affected:
- up to 3.7.4
- Fix:
- No patched version reported
- Disclosed:
- Jul 4, 2025
CVE-2025-28967 on NVD →
Contact Us Page – Contact People [contact-us-page-contact-people] <= 3.7.4 (unfixed + closed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Truman Contact Us page - Contact people LITE allows SQL Injection. This issue affects Contact Us page - Contact people LITE: from n/a through 3.7.4.
- Affected:
- up to 3.7.4
- Fix:
- No patched version reported
- Disclosed:
- Jul 4, 2025
CVE-2025-28967 on NVD →
Contact Us Page – Contact People <= 3.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via style Parameter
medium
The Contact Us Page – Contact People plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, and including, 3.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and a...
- CVSS:
- 6.4
- Affected:
- up to 3.7.4
- Fix:
- No patched version reported
- Disclosed:
- Jun 12, 2025
CVE-2025-5123 on NVD →
Contact Us Page – Contact People [contact-us-page-contact-people] < 3.7.1 (closed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Contact Us Page – Contact People plugin <= 3.7.0.
- Affected:
- up to 3.7.1
- Fixed in:
- 3.7.1
- Disclosed:
- Mar 1, 2023
CVE-2023-23973 on NVD →
Contact Us Page – Contact People <= 3.7.0 - Cross Site Request Forgery
medium
The Contact Us Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.0. This is due to missing or incorrect nonce validation on several functions handling the creation and updating of contacts. This makes it possible for unauthenticated attackers to invoke those fun...
- CVSS:
- 4.3
- Affected:
- up to 3.7.0
- Fixed in:
- 3.7.1
- Disclosed:
- Jan 20, 2023
CVE-2023-23973 on NVD →
a3 Lazy Load <= 2.6.0 - Cross-Site Request Forgery to Settings Reset
high
The following plugins for WordPress are vulnerable to Cross-Site Request Forgery:
a3 Lazy Load (<= 2.6.0), Contact Us Page – Contact People (<= 3.6.1), a3 Portfolio (<= 3.0.1), Dynamic Product Gallery for WooCommerce (3.0.1), a3 Responsive Slider (<= 2.2.0), Compare Products for WooCommerce (<= 2.8.2), Products Quic...
- CVSS:
- 8.8
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.2
- Disclosed:
- Nov 2, 2022
Contact Us Page – Contact People [contact-us-page-contact-people] < 3.6.2 (closed)
unknown
The following plugins for WordPress are vulnerable to Cross-Site Request Forgery:
a3 Lazy Load (<= 2.6.0), Contact Us Page – Contact People (<= 3.6.1), a3 Portfolio (<= 3.0.1), Dynamic Product Gallery for WooCommerce (3.0.1), a3 Responsive Slider (<= 2.2.0), Compare Products for WooCommerce (<= 2.8.2), Products Quic...
- Affected:
- up to 3.6.2
- Fixed in:
- 3.6.2
- Disclosed:
- Nov 2, 2022
Contact Us Page – Contact People <= 3.6.1 - Cross-Site Request Forgery to Settings Reset
high
The Contact Us Page – Contact People plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.1. This is due to missing or incorrect nonce validation on the reset_settings function. This makes it possible for unauthenticated attackers to rest the plugin to its defaults, via...
- CVSS:
- 8.8
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.2
- Disclosed:
- Nov 1, 2022
Contact Us Page – Contact People [contact-us-page-contact-people] < 3.6.2 (closed)
unknown
The Contact Us Page – Contact People plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.1. This is due to missing or incorrect nonce validation on the reset_settings function. This makes it possible for unauthenticated attackers to rest the plugin to its defaults, via...
- Affected:
- up to 3.6.2
- Fixed in:
- 3.6.2
- Disclosed:
- Nov 1, 2022
a3rev Multiple Plugins <= Various Versions - Cross-Site Request Forgery to Settings Changes
high
The a3 Lazy Load, a3 Portfolio, Contact Us Page – Contact People, Dynamic Product Gallery for WooCommerce, a3 Responsive Slider, and Compare Products for WooCommerce plugins for WordPress are vulnerable to Cross-Site Request Forgery respectively in versions up to, and including, 2.5.0, 3.0.0, 3.6.0, 2.9.0, 2.0.12, 2.8....
- CVSS:
- 8.8
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.1
- Disclosed:
- May 24, 2022
Contact Us Page – Contact People [contact-us-page-contact-people] < 3.6.1 (closed)
unknown
The a3 Lazy Load, a3 Portfolio, Contact Us Page – Contact People, Dynamic Product Gallery for WooCommerce, a3 Responsive Slider, and Compare Products for WooCommerce plugins for WordPress are vulnerable to Cross-Site Request Forgery respectively in versions up to, and including, 2.5.0, 3.0.0, 3.6.0, 2.9.0, 2.0.12, 2.8....
- Affected:
- up to 3.6.1
- Fixed in:
- 3.6.1
- Disclosed:
- May 24, 2022
Contact Us Page – Contact People [contact-us-page-contact-people] <= 3.7.4 (unfixed + closed)
unknown
- Affected:
- up to 3.7.4
- Fix:
- No patched version reported
CVE-2025-5123 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database