First published: Tue Jun 04 2024(Updated: )
Missing Authorization vulnerability in CodePeople Contact Form Email allows Functionality Misuse.This issue affects Contact Form Email: from n/a through 1.3.31.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
CodePeople Contact Form Email | <1.3.32 | |
CodePeople Contact Form Email | <=1.3.31 | |
WordPress Contact Form Email | <=1.3.31 |
Update to 1.3.32 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28494 is classified as a missing authorization vulnerability that could lead to functionality misuse in the affected version of CodePeople Contact Form Email.
To fix CVE-2023-28494, upgrade CodePeople Contact Form Email to version 1.3.32 or later where the vulnerability has been addressed.
CVE-2023-28494 affects all versions of CodePeople Contact Form Email up to and including 1.3.31.
If CVE-2023-28494 is not addressed, it could allow unauthorized users to misuse the contact form functionality.
Any user of the CodePeople Contact Form Email plugin for WordPress versions up to 1.3.31 is impacted by CVE-2023-28494.