CVE-2026-32483
Contact Form Email
Minimum safe version
1.3.64
Update to 1.3.64 or later to address 22 fixable vulnerabilities
CVE-2025-10019
Contact Form Email <= 1.3.58 - Missing Authorization
CVE-2025-24727
CVE-2024-31302
WordPress Contact Form Email Plugin < 1.3.44 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-48318
WordPress Contact Form Email Plugin < 1.3.38 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-28494
Contact Form Email <= 1.3.31 - Cross-Site Request Forgery to Feedback Submission
Contact Form Email < 1.0.1 - Cross-Site Scripting
Contact Form Email <= 1.3.11 - Cross-Site Request Forgery to Cross-Site Scripting
Contact Form Email < 1.1.48 - Reflected Cross-Site Scripting
wpscan.com
Contact Form to Email <= 1.1.47 - Authenticated Reflected Cross-Site Scripting (XSS)
WordPress Contact Form To Email Plugin <= 1.1.4 - Multiple Vulnerabilities
WordPress Contact Form To Email Plugin <= 1.1.4 - Multiple Vulnerabilities
WordPress Contact Form To Email Plugin <= 1.1.47 - Cross Site Scripting
WordPress Contact Form Email plugin <= 1.2.65 - Cross-Site Scripting (XSS) vulnerability
CVE-2018-20964
CVE-2018-20963
CVE-2021-42361