This page lists publicly disclosed CVE vulnerabilities affecting codepeople cp_contact_form_with_paypal (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-27460 | Missing Authorization vulnerability in CodePeople, paypaldev CP Contact Form with Paypal allows Functionality Misuse.This issue affects CP Contact Form with Paypal: from n/a through 1.3.34. | [email protected] | 4.3 | 0.38% | 2024-06-03 | 2026-06-17 |
| CVE-2019-14784 | The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition. | [email protected] | 6.1 | 0.94% | 2019-08-15 | 2026-06-16 |
| CVE-2019-14785 | The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter. | [email protected] | 5.4 | 0.80% | 2019-08-09 | 2026-06-16 |
| CVE-2015-9233 | The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php. | [email protected] | 8.8 | 1.01% | 2017-09-29 | 2026-06-16 |