Extension WordPress
Vulnérabilités CP Contact Form with PayPal
Cette page rassemble les failles publiées pour CP Contact Form with PayPal, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de CP Contact Form with PayPal
8 fiches
CP Contact Form with Paypal <= 1.3.61 – Authenticated (Contributor+) SQL Injection
The CP Contact Form with Paypal plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.3.61 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
*-1.3.61
1.3.62
02/03/2026
CP Contact Form with PayPal <= 1.3.56 – Missing Authorization to Unauthenticated Arbitrary Payment Confirmation
The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.3.56. This is due to the plugin exposing an unauthenticated IPN-like endpoint (via the 'cp_contactformpp_ipncheck' query parameter)…
*-1.3.56
1.3.57
21/11/2025
CP Contact Form with PayPal <= 1.3.52 – Cross-Site Request Forgery
The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.52. This is due to missing or incorrect nonce validation on the cp_contact_form_paypal_check_init_actions() function. This makes…
*-1.3.52
1.3.53
29/01/2025
CP Contact Form with Paypal <= 1.3.34 – Authenticated Feedback Submission
The CP Contact Form with Paypal plugin for WordPress is vulnerable to missing authorization on the 'cpcfwpp_feedback' function in versions up to, and including, 1.3.34. This allows authenticated attackers, with subscriber-level capabilities or above, to submit feedback to…
*-1.3.34
1.3.35
01/03/2023
CP Contact Form with PayPal <= 1.3.01 – Cross-Site Scripting
The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter.
[*, 1.3.02)
1.3.02
23/06/2019
CP Contact Form with PayPal <= 1.3.01 – Cross-Site Scripting
The "CP Contact Form with PayPal" plugin before 1.3.02 for WordPress has XSS in CSS edition.
*-1.3.01
1.3.02
23/06/2019
CP Contact Form with PayPal < 1.1.6 – SQL Injection
The CP Contact Form with PayPal plugin for WordPress is vulnerable to SQL Injection via the 'cp_contactformpp_id' parameter found in the 'cp_contactformpp.php' file in versions up to 1.1.6 due to insufficient escaping on the user supplied parameter and…
[*, 1.1.6)
1.1.6
09/07/2015
CP Contact Form with PayPal < 1.1.6 – Cross-Site Request Forgery
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php.
[*, 1.1.6)
1.1.6
09/07/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.