Extension WordPress

Vulnérabilités CP Contact Form with PayPal

Cette page rassemble les failles publiées pour CP Contact Form with PayPal, leurs plages de versions affectées et les correctifs signalés dans la base locale.

8Vulnérabilités
0Critiques
8Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de CP Contact Form with PayPal

8 fiches

CVE-2025-13384 Élevée · 7,5
CP Contact Form with PayPal

CP Contact Form with PayPal <= 1.3.56 – Missing Authorization to Unauthenticated Arbitrary Payment Confirmation

The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.56. This is due to the plugin exposing an unauthenticated IPN-like endpoint (via the 'cp_contactformpp_ipncheck' query parameter)…

Versions affectées

*-1.3.56

Correctif

1.3.57

Publication

21/11/2025

CVE-2023-27460 Moyenne · 4,3
CP Contact Form with PayPal

CP Contact Form with Paypal <= 1.3.34 – Authenticated Feedback Submission

The CP Contact Form with Paypal plugin for WordPress is vulnerable to missing authorization on the 'cpcfwpp_feedback' function in versions up to, and including, 1.3.34. This allows authenticated attackers, with subscriber-level capabilities or above, to submit feedback to…

Versions affectées

*-1.3.34

Correctif

1.3.35

Publication

01/03/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités