Vulnerabilities (CVE)

Filtered by vendor Codepeople Subscribe
Filtered by product Cp Contact Form With Paypal
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-14785 1 Codepeople 1 Cp Contact Form With Paypal 2024-02-28 3.5 LOW 5.4 MEDIUM
The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter.
CVE-2019-14784 1 Codepeople 1 Cp Contact Form With Paypal 2024-02-28 4.3 MEDIUM 6.1 MEDIUM
The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.
CVE-2015-9233 1 Codepeople 1 Cp Contact Form With Paypal 2024-02-28 6.8 MEDIUM 8.8 HIGH
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php.