← WordPress Vulnerabilities
WordPress security by component

Contact Form Email

Contact Form Email is a WordPress component with 9 published CVE records in this archive. The latest tracked vulnerability was published Mar 25, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: contact-form-to-email

CVE-2026-32483: Contact Form Email: A security weakness

Contact Form Email is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through <= 1.3.63.

PublishedMar 25, 2026
Known safe version1.3.64
Safe version
Mar 25, 2026 CVE-2026-32483
Contact Form Email: A security weakness
Contact Form Email is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through <= 1.3.63.
1.3.64
CVE6.5
NVDPending
Dec 18, 2025 CVE-2025-10019
Contact Form Email: A security weakness
Contact Form Email is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Nov 13, 2025 CVE-2025-64369
Contact Form Email: A security weakness
Contact Form Email is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Jun 04, 2024 CVE-2023-48318
Contact Form Email: A security weakness
Contact Form Email is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD6.5
Jun 04, 2024 CVE-2023-28494
Contact Form Email: A security weakness
Contact Form Email is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Apr 10, 2024 CVE-2024-31302
Contact Form Email: A security weakness
Contact Form Email is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Aug 13, 2019 CVE-2018-20964
Contact Form To Email: Cross-site request forgery
Contact Form To Email is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8
Aug 13, 2019 CVE-2018-20963
Contact Form To Email: Cross-site scripting
Contact Form To Email is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Mar 10, 2019 CVE-2019-9646
Contact Form To Email: Cross-site scripting
Contact Form To Email is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1