CVE-2025-64369: WordPress Contact Form Email plugin <= 1.3.58 - Broken Access Control vulnerability
Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through <= 1.3.58.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64369?
CVE-2025-64369 is classified as a missing authorization vulnerability that may lead to potential unauthorized access.
How do I fix CVE-2025-64369?
To fix CVE-2025-64369, update the Contact Form Email plugin to the latest version beyond 1.3.58 that addresses this vulnerability.
What versions are affected by CVE-2025-64369?
CVE-2025-64369 affects the Contact Form Email plugin from any version up to and including 1.3.58.
What are the implications of CVE-2025-64369 for my WordPress site?
Exploitation of CVE-2025-64369 could allow attackers to gain unauthorized access to sensitive data submitted through the contact form.
Is there a patch available for CVE-2025-64369?
Yes, a patch is available in the latest versions of the Contact Form Email plugin that resolves the missing authorization issue of CVE-2025-64369.