CVE-2019-9646: XSS
Published Mar 10, 2019
·Updated
The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cpadminintedition.inc.php in the "custom edition area."
Affected Software
1 affected component
CodePeople Contact Form Email Wordpress<1.2.66
Event History
Mar 10, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9646?
CVE-2019-9646 is classified as a low-severity vulnerability that allows for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2019-9646?
To fix CVE-2019-9646, update the Contact Form Email plugin to version 1.2.66 or later.
3
What types of attacks does CVE-2019-9646 allow?
CVE-2019-9646 allows attackers to perform XSS attacks through the wp-admin/admin.php interface.
4
Which versions of the Contact Form Email plugin are affected by CVE-2019-9646?
CVE-2019-9646 affects all versions of the Contact Form Email plugin prior to 1.2.66.
5
What components are involved in CVE-2019-9646?
CVE-2019-9646 specifically involves the cp_admin_int_edition.inc.php file in the custom edition area of the plugin.