CVE-2015-9233: Codepeople CP Contact Form With PayPal
High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has CSRF with resultant XSS, related to cp_contactformpp.php and cp_contactformpp_admin_int_list.inc.php.
Affected products
- Codepeople CP Contact Form With PayPal: before 1.1.6 (fixed in 1.1.6)
Published 2017-09-30. Last modified 2026-06-17.