High 7.1
2026-03-25< 9.1.1
CVE-2026-32517
Minimum safe version
9.1.1
Update to 9.1.1 or later to address 3 fixable vulnerabilities
CVE-2026-32517
CVE-2025-68853
Contact Manager <= 8.6.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'title'
WordPress Contact Manager Plugin <= 8.6.4 is vulnerable to Arbitrary File Upload