CVE-2018-20964: CSRF
Published Aug 13, 2019
·Updated
The contact-form-to-email plugin before 1.2.66 for WordPress has CSRF.
Affected Software
1 affected component
CodePeople Contact Form Email Wordpress<1.2.66
Event History
Aug 13, 2019
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-20964?
CVE-2018-20964 is classified as a medium-severity vulnerability due to its potential for CSRF attacks.
2
How do I fix CVE-2018-20964?
To fix CVE-2018-20964, update the contact-form-to-email plugin to version 1.2.66 or later.
3
What type of vulnerability is CVE-2018-20964?
CVE-2018-20964 is a Cross-Site Request Forgery (CSRF) vulnerability.
4
What software is affected by CVE-2018-20964?
CVE-2018-20964 affects the contact-form-to-email plugin versions before 1.2.66 for WordPress.
5
Can CVE-2018-20964 lead to data leakage?
Yes, CVE-2018-20964 can potentially lead to unauthorized actions being performed on behalf of the user, which may lead to data exposure.