Input validation vulnerability in WP-ContactForm 1.5.1

The WP-ContactForm 1.5 alpha and earlier plugin for WordPress has multiple vulnerabilities that allow remote attackers to perform certain actions as if they were an administrator. This can be done by sending specially crafted requests to the wp-admin/admin.php page with one of the parameters wpcf_question

Detected in:

WP-ContactForm fixed vulnerable versions: >= * <= 1.5.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.