plugin

Contact Us Page Contact People Vulnerabilities

12 known security issues reported for the Contact Us Page Contact People WordPress plugin. Most recent disclosed Jul 4, 2025.

3 high 3 medium

Running Contact Us Page Contact People on your site? Check whether your installed version is affected.

Scan your site free

Contact Us page - Contact people LITE <= 3.7.4 - Authenticated (Contributor+) SQL Injection

medium

The Contact Us page - Contact people LITE plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.7.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contri...

CVSS:
6.5
Affected:
up to 3.7.4
Fix:
No patched version reported
Disclosed:
Jul 4, 2025

CVE-2025-28967 on NVD →

Contact Us Page &#8211; Contact People [contact-us-page-contact-people] <= 3.7.4 (unfixed + closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Truman Contact Us page - Contact people LITE allows SQL Injection. This issue affects Contact Us page - Contact people LITE: from n/a through 3.7.4.

Affected:
up to 3.7.4
Fix:
No patched version reported
Disclosed:
Jul 4, 2025

CVE-2025-28967 on NVD →

Contact Us Page – Contact People <= 3.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via style Parameter

medium

The Contact Us Page – Contact People plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, and including, 3.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and a...

CVSS:
6.4
Affected:
up to 3.7.4
Fix:
No patched version reported
Disclosed:
Jun 12, 2025

CVE-2025-5123 on NVD →

Contact Us Page &#8211; Contact People [contact-us-page-contact-people] < 3.7.1 (closed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Contact Us Page – Contact People plugin <= 3.7.0.

Affected:
up to 3.7.1
Fixed in:
3.7.1
Disclosed:
Mar 1, 2023

CVE-2023-23973 on NVD →

Contact Us Page – Contact People <= 3.7.0 - Cross Site Request Forgery

medium

The Contact Us Page plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.0. This is due to missing or incorrect nonce validation on several functions handling the creation and updating of contacts. This makes it possible for unauthenticated attackers to invoke those fun...

CVSS:
4.3
Affected:
up to 3.7.0
Fixed in:
3.7.1
Disclosed:
Jan 20, 2023

CVE-2023-23973 on NVD →

a3 Lazy Load <= 2.6.0 - Cross-Site Request Forgery to Settings Reset

high

The following plugins for WordPress are vulnerable to Cross-Site Request Forgery: a3 Lazy Load (<= 2.6.0), Contact Us Page – Contact People (<= 3.6.1), a3 Portfolio (<= 3.0.1), Dynamic Product Gallery for WooCommerce (3.0.1), a3 Responsive Slider (<= 2.2.0), Compare Products for WooCommerce (<= 2.8.2), Products Quic...

CVSS:
8.8
Affected:
up to 3.6.1
Fixed in:
3.6.2
Disclosed:
Nov 2, 2022

Contact Us Page &#8211; Contact People [contact-us-page-contact-people] < 3.6.2 (closed)

unknown

The following plugins for WordPress are vulnerable to Cross-Site Request Forgery: a3 Lazy Load (<= 2.6.0), Contact Us Page – Contact People (<= 3.6.1), a3 Portfolio (<= 3.0.1), Dynamic Product Gallery for WooCommerce (3.0.1), a3 Responsive Slider (<= 2.2.0), Compare Products for WooCommerce (<= 2.8.2), Products Quic...

Affected:
up to 3.6.2
Fixed in:
3.6.2
Disclosed:
Nov 2, 2022

Contact Us Page – Contact People <= 3.6.1 - Cross-Site Request Forgery to Settings Reset

high

The Contact Us Page – Contact People plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.1. This is due to missing or incorrect nonce validation on the reset_settings function. This makes it possible for unauthenticated attackers to rest the plugin to its defaults, via...

CVSS:
8.8
Affected:
up to 3.6.1
Fixed in:
3.6.2
Disclosed:
Nov 1, 2022

Contact Us Page &#8211; Contact People [contact-us-page-contact-people] < 3.6.2 (closed)

unknown

The Contact Us Page – Contact People plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.1. This is due to missing or incorrect nonce validation on the reset_settings function. This makes it possible for unauthenticated attackers to rest the plugin to its defaults, via...

Affected:
up to 3.6.2
Fixed in:
3.6.2
Disclosed:
Nov 1, 2022

a3rev Multiple Plugins <= Various Versions - Cross-Site Request Forgery to Settings Changes

high

The a3 Lazy Load, a3 Portfolio, Contact Us Page – Contact People, Dynamic Product Gallery for WooCommerce, a3 Responsive Slider, and Compare Products for WooCommerce plugins for WordPress are vulnerable to Cross-Site Request Forgery respectively in versions up to, and including, 2.5.0, 3.0.0, 3.6.0, 2.9.0, 2.0.12, 2.8....

CVSS:
8.8
Affected:
up to 3.6.0
Fixed in:
3.6.1
Disclosed:
May 24, 2022

Contact Us Page &#8211; Contact People [contact-us-page-contact-people] < 3.6.1 (closed)

unknown

The a3 Lazy Load, a3 Portfolio, Contact Us Page – Contact People, Dynamic Product Gallery for WooCommerce, a3 Responsive Slider, and Compare Products for WooCommerce plugins for WordPress are vulnerable to Cross-Site Request Forgery respectively in versions up to, and including, 2.5.0, 3.0.0, 3.6.0, 2.9.0, 2.0.12, 2.8....

Affected:
up to 3.6.1
Fixed in:
3.6.1
Disclosed:
May 24, 2022

Contact Us Page &#8211; Contact People [contact-us-page-contact-people] <= 3.7.4 (unfixed + closed)

unknown
Affected:
up to 3.7.4
Fix:
No patched version reported

CVE-2025-5123 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database