← WordPress Vulnerabilities
WordPress security by component

Contact Form Maker

Contact Form Maker is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jun 04, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: contact-form-maker

CVE-2019-25734: Contact Form Maker: Filesystem traversal

Contact Form Maker is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is 1.13.1.

PublishedJun 04, 2026
Safe version guidanceSee mitigation notes
Safe version
Jun 04, 2026 CVE-2019-25734
Contact Form Maker: Filesystem traversal
Contact Form Maker is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is 1.13.1.
See mitigation notes
CVE5.1
NVDPending
May 23, 2026 CVE-2018-25347
Contact Form Maker: SQL injection
Contact Form Maker is affected by SQL injection. Exploitation requires an authenticated WordPress account. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.12.20.
> 1.12.20
CVE7.1
NVDPending
Jan 16, 2024 CVE-2023-2655
Contact Form by WD: SQL injection
Contact Form by WD is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2
Apr 29, 2019 CVE-2019-11591
Contact Form Maker: Filesystem traversal
Contact Form Maker is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.8
NVD8.8