plugin

Stickeasy Protected Contact Form Vulnerabilities

1 known security issue reported for the Stickeasy Protected Contact Form WordPress plugin. Most recent disclosed Feb 13, 2026.

1 medium

Running Stickeasy Protected Contact Form on your site? Check whether your installed version is affected.

Scan your site free

StickEasy Protected Contact Form <= 1.0.1 - Unauthenticated Information Disclosure

medium

The StickEasy Protected Contact Form plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.0.2. The plugin stores spam detection logs at a predictable publicly accessible location (wp-content/uploads/stickeasy-protected-contact-form/spcf-log.txt). This makes it p...

CVSS:
5.3
Affected:
up to 1.0.1
Fixed in:
1.0.2
Disclosed:
Feb 13, 2026

CVE-2025-13973 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database