Creative Contact Form [sexy-contact-form] <= 1.0.0 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Creative-Solutions Creative Contact Form allows Stored XSS. This issue affects Creative Contact Form: from n/a through 1.0.0.
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 20, 2025
CVE-2025-52794 on NVD →
Creative Contact Form <= 1.0.0 - Cross-Site Request Forgery
medium
The Creative Contact Form plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action granted they can trick a site...
- CVSS:
- 4.3
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 19, 2025
CVE-2025-52794 on NVD →
Creative Contact Form [sexy-contact-form] < 1.0.0
unknown
[en] Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code b...
- Affected:
- up to 1.0.0
- Fixed in:
- 1.0.0
- Disclosed:
- Feb 8, 2020
CVE-2014-8739 on NVD →
Creative Contact Form [sexy-contact-form] < 0.9.8
unknown
This vulnerability allows an attacker to upload arbitrary PHP code and execute it.
Update the plugin.
- Affected:
- up to 0.9.8
- Fixed in:
- 0.9.8
- Disclosed:
- Apr 21, 2015
Creative Contact Form < 1.0.0 - Arbitrary File Upload
critical
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by upl...
- CVSS:
- 9.8
- Affected:
- up to 1.0.0
- Fixed in:
- 1.0.0
- Disclosed:
- Oct 23, 2014
CVE-2014-8739 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database