Vulnerabilities > Codepeople > CP Contact Form With Paypal > 1.1.3

DATE CVE VULNERABILITY TITLE RISK
2019-08-15 CVE-2019-14784 Cross-site Scripting vulnerability in Codepeople CP Contact Form With Paypal
The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.
network
codepeople CWE-79
4.3
2019-08-09 CVE-2019-14785 Cross-site Scripting vulnerability in Codepeople CP Contact Form With Paypal
The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter.
network
codepeople CWE-79
3.5
2017-09-30 CVE-2015-9233 Cross-Site Request Forgery (CSRF) vulnerability in Codepeople CP Contact Form With Paypal
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php.
6.8