First published: Sun Mar 10 2019(Updated: )
The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area."
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CodePeople Contact Form Email | <1.2.66 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9646 is classified as a low-severity vulnerability that allows for cross-site scripting (XSS) attacks.
To fix CVE-2019-9646, update the Contact Form Email plugin to version 1.2.66 or later.
CVE-2019-9646 allows attackers to perform XSS attacks through the wp-admin/admin.php interface.
CVE-2019-9646 affects all versions of the Contact Form Email plugin prior to 1.2.66.
CVE-2019-9646 specifically involves the cp_admin_int_edition.inc.php file in the custom edition area of the plugin.