PT-2019-13830 · WordPress · Cp Contact Form With Paypal

Joaquin Ramirez Martinez

·

Published

2019-08-09

·

Updated

2019-08-15

·

CVE-2019-14785

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CP Contact Form with PayPal plugin versions prior to 1.2.99
Description The issue concerns a Cross-Site Scripting (XSS) flaw in the publishing wizard of the plugin. This is accessible via the "wp-admin/admin.php?page=cp contact form paypal.php&pwizard=1" endpoint, specifically through the cp contactformpp id parameter.
Recommendations For versions prior to 1.2.99, update to version 1.2.99 or later to resolve the issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14785

Affected Products

Cp Contact Form With Paypal