Black Friday Deals 40% OFF

Days
Hours
Minutes

Input validation vulnerability in Contact Form Email 1.1.48

The Contact Form Email plugin for WordPress is vulnerable to a type of cyber attack called Reflected Cross-Site Scripting. This security issue affects versions of the plugin before 1.1.48. It is caused by a lack of protection that would prevent malicious code from being input and output. This means that unauthorised attackers can insert malicious scripts into webpages, which can be triggered if the user takes a certain action, such as clicking a link.

Detected in:

Contact Form Email fixed vulnerable versions: >= * < 1.1.48

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.