First published: Fri Aug 09 2019(Updated: )
The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cfpaypal Cp Contact Form With Paypal | <1.2.99 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14785 has been classified as a medium severity vulnerability due to its potential to allow reflected Cross-Site Scripting (XSS) attacks.
To fix CVE-2019-14785, you should update the "CP Contact Form with PayPal" plugin to version 1.2.99 or later.
CVE-2019-14785 can facilitate reflected Cross-Site Scripting (XSS) attacks, potentially allowing unauthorized actions or data theft.
CVE-2019-14785 affects versions of the "CP Contact Form with PayPal" plugin prior to 1.2.99.
The vulnerability CVE-2019-14785 occurs in the publishing wizard of the "CP Contact Form with PayPal" plugin within the WordPress admin interface.