CVE-2023-28494: WordPress Contact Form Email plugin <= 1.3.31 - Missing Authorization Leading To Feedback Submission Vulnerability
Missing Authorization vulnerability in CodePeople Contact Form Email allows Functionality Misuse.This issue affects Contact Form Email: from n/a through 1.3.31.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-28494?
CVE-2023-28494 is classified as a missing authorization vulnerability that could lead to functionality misuse in the affected version of CodePeople Contact Form Email.
How do I fix CVE-2023-28494?
To fix CVE-2023-28494, upgrade CodePeople Contact Form Email to version 1.3.32 or later where the vulnerability has been addressed.
Which versions are affected by CVE-2023-28494?
CVE-2023-28494 affects all versions of CodePeople Contact Form Email up to and including 1.3.31.
What can happen if I don't address CVE-2023-28494?
If CVE-2023-28494 is not addressed, it could allow unauthorized users to misuse the contact form functionality.
Who is impacted by CVE-2023-28494?
Any user of the CodePeople Contact Form Email plugin for WordPress versions up to 1.3.31 is impacted by CVE-2023-28494.