Report
The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area."
Score:6.1
Severity:Medium
Version: 1.2.65
There is a patch available in v1.2.66 and we strongly recommend you update to this version as soon as possible.