CP Contact Form with PayPal [cp-contact-form-with-paypal] <= 1.3.61 (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople CP Contact Form with Paypal cp-contact-form-with-paypal allows Blind SQL Injection.This issue affects CP Contact Form with Paypal: from n/a through <= 1.3.61.
- Affected:
- up to 1.3.61
- Fix:
- No patched version reported
- Disclosed:
- Mar 13, 2026
CVE-2026-32433 on NVD →
CP Contact Form with Paypal <= 1.3.61 - Authenticated (Contributor+) SQL Injection
medium
The CP Contact Form with Paypal plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.61 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-leve...
- CVSS:
- 6.5
- Affected:
- up to 1.3.61
- Fixed in:
- 1.3.62
- Disclosed:
- Mar 2, 2026
CVE-2026-32433 on NVD →
CP Contact Form with PayPal [cp-contact-form-with-paypal] < 1.3.57
unknown
[en] The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.56. This is due to the plugin exposing an unauthenticated IPN-like endpoint (via the 'cp_contactformpp_ipncheck' query parameter) that processes payment confirmations without any au...
- Affected:
- up to 1.3.57
- Fixed in:
- 1.3.57
- Disclosed:
- Nov 22, 2025
CVE-2025-13384 on NVD →
CP Contact Form with PayPal <= 1.3.56 - Missing Authorization to Unauthenticated Arbitrary Payment Confirmation
high
The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.56. This is due to the plugin exposing an unauthenticated IPN-like endpoint (via the 'cp_contactformpp_ipncheck' query parameter) that processes payment confirmations without any authent...
- CVSS:
- 7.5
- Affected:
- up to 1.3.56
- Fixed in:
- 1.3.57
- Disclosed:
- Nov 21, 2025
CVE-2025-13384 on NVD →
CP Contact Form with PayPal [cp-contact-form-with-paypal] < 1.3.53
unknown
[en] The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.52. This is due to missing or incorrect nonce validation on the cp_contact_form_paypal_check_init_actions() function. This makes it possible for unauthenticated attackers to ad...
- Affected:
- up to 1.3.53
- Fixed in:
- 1.3.53
- Disclosed:
- Jan 30, 2025
CVE-2024-13758 on NVD →
CP Contact Form with PayPal <= 1.3.52 - Cross-Site Request Forgery
medium
The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.52. This is due to missing or incorrect nonce validation on the cp_contact_form_paypal_check_init_actions() function. This makes it possible for unauthenticated attackers to add dis...
- CVSS:
- 6.5
- Affected:
- up to 1.3.52
- Fixed in:
- 1.3.53
- Disclosed:
- Jan 29, 2025
CVE-2024-13758 on NVD →
CP Contact Form with PayPal [cp-contact-form-with-paypal] < 1.3.35
unknown
[en] Missing Authorization vulnerability in CodePeople, paypaldev CP Contact Form with Paypal allows Functionality Misuse.This issue affects CP Contact Form with Paypal: from n/a through 1.3.34.
- Affected:
- up to 1.3.35
- Fixed in:
- 1.3.35
- Disclosed:
- Jun 3, 2024
CVE-2023-27460 on NVD →
CP Contact Form with Paypal <= 1.3.34 - Authenticated Feedback Submission
medium
The CP Contact Form with Paypal plugin for WordPress is vulnerable to missing authorization on the 'cpcfwpp_feedback' function in versions up to, and including, 1.3.34. This allows authenticated attackers, with subscriber-level capabilities or above, to submit feedback to the plugin developers, which is intended to be...
- CVSS:
- 4.3
- Affected:
- up to 1.3.34
- Fixed in:
- 1.3.35
- Disclosed:
- Mar 1, 2023
CVE-2023-27460 on NVD →
CP Contact Form with PayPal [cp-contact-form-with-paypal] < 1.3.02
unknown
[en] The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.
- Affected:
- up to 1.3.02
- Fixed in:
- 1.3.02
- Disclosed:
- Aug 15, 2019
CVE-2019-14784 on NVD →
CP Contact Form with PayPal [cp-contact-form-with-paypal] < 1.3.02
unknown
[en] The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter.
- Affected:
- up to 1.3.02
- Fixed in:
- 1.3.02
- Disclosed:
- Aug 9, 2019
CVE-2019-14785 on NVD →
CP Contact Form with PayPal [cp-contact-form-with-paypal] < 1.2.98
unknown
Authenticated Cross-Site Scripting (XSS) vulnerability found in WordPress CP Contact Form with Paypal plugin (versions <= 1.2.97).
- Affected:
- up to 1.2.98
- Fixed in:
- 1.2.98
- Disclosed:
- Jun 25, 2019
CP Contact Form with PayPal <= 1.3.01 - Cross-Site Scripting
medium
The "CP Contact Form with PayPal" plugin before 1.3.02 for WordPress has XSS in CSS edition.
- CVSS:
- 6.1
- Affected:
- up to 1.3.01
- Fixed in:
- 1.3.02
- Disclosed:
- Jun 23, 2019
CVE-2019-14784 on NVD →
CP Contact Form with PayPal <= 1.3.01 - Cross-Site Scripting
medium
The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter.
- CVSS:
- 5.4
- Affected:
- up to 1.3.02
- Fixed in:
- 1.3.02
- Disclosed:
- Jun 23, 2019
CVE-2019-14785 on NVD →
CP Contact Form with PayPal [cp-contact-form-with-paypal] < 1.1.6
unknown
[en] The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php.
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.6
- Disclosed:
- Sep 29, 2017
CVE-2015-9233 on NVD →
CP Contact Form with PayPal [cp-contact-form-with-paypal] < 1.1.6
unknown
[en] The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has SQL injection via the cp_contactformpp_id parameter to cp_contactformpp.php.
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.6
- Disclosed:
- Sep 29, 2017
CVE-2015-9234 on NVD →
CP Contact Form with PayPal [cp-contact-form-with-paypal] < 1.1.6
unknown
There are multiple vulnerabilities in this plugin, such as CSRF, XSS and SQL injection. These vulnerabilities allow an attacker to add or delete forms, export CSV files of the messages and modify settings of the form.
Upgrade to version 1.1.6.
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.6
- Disclosed:
- Jul 13, 2015
CP Contact Form with PayPal < 1.1.6 - Cross-Site Request Forgery
high
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php.
- CVSS:
- 8.8
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.6
- Disclosed:
- Jul 9, 2015
CVE-2015-9233 on NVD →
CP Contact Form with PayPal < 1.1.6 - SQL Injection
high
The CP Contact Form with PayPal plugin for WordPress is vulnerable to SQL Injection via the 'cp_contactformpp_id' parameter found in the 'cp_contactformpp.php' file in versions up to 1.1.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This ma...
- CVSS:
- 7.2
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.6
- Disclosed:
- Jul 9, 2015
CVE-2015-9234 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database