Codepeople
Codepeople CP Contact Form With Paypal: vulnerabilities and CVEs
Codepeople CP Contact Form With Paypal has 5 published vulnerabilities, 1 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs5
Last 12 months1
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-32433 | High (8.5) | 0.36% | — | Mar 13, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople CP Contact Form with Paypal cp-contact-form-with-paypal allows Blind SQL Injection.This issue affects CP… |
| CVE-2023-27460 | High (8.8) | 0.38% | — | Jun 3, 2024 | Missing Authorization vulnerability in CodePeople, paypaldev CP Contact Form with Paypal allows Functionality Misuse.This issue affects CP Contact Form with Paypal: from n/a through 1.3.34. |
| CVE-2019-14784 | Medium (6.1) | 0.94% | — | Aug 15, 2019 | The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition. |
| CVE-2019-14785 | Medium (5.4) | 0.80% | — | Aug 9, 2019 | The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter. |
| CVE-2015-9233 | High (8.8) | 1.0% | — | Sep 30, 2017 | The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.