Beta

Report

Contact Form Email <= 1.2.65 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability

Unauthenticated
Published
2019-03-11

The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area."

CVSS

Score:6.1

Severity:Medium

Version: 1.2.65

There is a patch available in v1.2.66 and we strongly recommend you update to this version as soon as possible.