CVE-2024-31302: WordPress Contact Form Email plugin <= 1.3.44 - Sensitive Data Exposure vulnerability
Published Apr 10, 2024
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodePeople Contact Form Email.This issue affects Contact Form Email: from n/a through 1.3.44.
Affected Software
1 affected component
CodePeople Contact Form Email Wordpress<1.3.44
Remediation
Information
Update to 1.3.45 or a higher version.
Event History
Apr 10, 2024
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-31302?
CVE-2024-31302 has been rated as a moderate severity vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2024-31302?
To fix CVE-2024-31302, update the CodePeople Contact Form Email plugin to the latest version beyond 1.3.44.
3
What type of information is exposed in CVE-2024-31302?
CVE-2024-31302 exposes sensitive information to unauthorized actors, which can include personal data submitted through the contact form.
4
Which versions of the software are affected by CVE-2024-31302?
CVE-2024-31302 affects CodePeople Contact Form Email versions from n/a through 1.3.44.
5
Who is impacted by CVE-2024-31302?
Users of the vulnerable versions of the CodePeople Contact Form Email plugin on WordPress are impacted by CVE-2024-31302.