CVE-2015-9233: Codepeople CP Contact Form With PayPal

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php.

Affected products

  • Codepeople CP Contact Form With PayPal: before 1.1.6 (fixed in 1.1.6)

Published 2017-09-30. Last modified 2026-06-17.