StickEasy Protected Contact Form <= 1.0.1 - Unauthenticated Information Disclosure
mediumThe StickEasy Protected Contact Form plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 1.0.2. The plugin stores spam detection logs at a predictable publicly accessible location (wp-content/uploads/stickeasy-protected-contact-form/spcf-log.txt). This makes it p...
- CVSS:
- 5.3
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.2
- Disclosed:
- Feb 13, 2026