CVE-2015-9233: XSS
Published Sep 29, 2017
·Updated
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cpcontactformpp.php and cpcontactformppadminintlist.inc.php.
Affected Software
1 affected component
CodePeople Cp Contact Form With Paypal Wordpress<1.1.6
Event History
Sep 29, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9233?
CVE-2015-9233 is classified as a medium severity vulnerability due to its CSRF and resultant XSS impact.
2
How do I fix CVE-2015-9233?
To fix CVE-2015-9233, upgrade the cp-contact-form-with-paypal plugin to version 1.1.6 or later.
3
What are the consequences of CVE-2015-9233?
The consequences of CVE-2015-9233 include potential unauthorized actions and scripts being executed in the context of the user.
4
Which versions of the cp-contact-form-with-paypal plugin are affected by CVE-2015-9233?
All versions of the cp-contact-form-with-paypal plugin prior to 1.1.6 are affected by CVE-2015-9233.
5
Is CVE-2015-9233 specific to WordPress?
Yes, CVE-2015-9233 specifically affects the cp-contact-form-with-paypal plugin used within WordPress.