WordPress security by component
Contact Form Email
Plugin description
Contact Form Email is a WordPress component with 9 published CVE records in this archive. The latest tracked vulnerability was published Mar 25, 2026; the highest CVE/CNA score is 8.8.
Plugin slug:
contact-form-to-emailLatest vulnerability
CVE-2026-32483: Contact Form Email: A security weakness
Contact Form Email is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through <= 1.3.63.
| Safe version |
|
||
|---|---|---|---|
| Mar 25, 2026 |
CVE-2026-32483
Contact Form Email: A security weakness
Contact Form Email is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through <= 1.3.63.
|
1.3.64 |
CVE6.5
NVDPending
|
| Dec 18, 2025 |
CVE-2025-10019
Contact Form Email: A security weakness
Contact Form Email is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Nov 13, 2025 |
CVE-2025-64369
Contact Form Email: A security weakness
Contact Form Email is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jun 04, 2024 |
CVE-2023-48318
Contact Form Email: A security weakness
Contact Form Email is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD6.5
|
| Jun 04, 2024 |
CVE-2023-28494
Contact Form Email: A security weakness
Contact Form Email is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 10, 2024 |
CVE-2024-31302
Contact Form Email: A security weakness
Contact Form Email is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Aug 13, 2019 |
CVE-2018-20964
Contact Form To Email: Cross-site request forgery
Contact Form To Email is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Aug 13, 2019 |
CVE-2018-20963
Contact Form To Email: Cross-site scripting
Contact Form To Email is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Mar 10, 2019 |
CVE-2019-9646
Contact Form To Email: Cross-site scripting
Contact Form To Email is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|