CVE-2015-9234: Cfpaypal CP Contact Form With PayPal
High severity, CVSS 7.2. EPSS: 2% chance of exploitation in the next 30 days.
The cp-contact-form-with-paypal (aka CP Contact Form with PayPal) plugin before 1.1.6 for WordPress has SQL injection via the cp_contactformpp_id parameter to cp_contactformpp.php.
Affected products
- Cfpaypal CP Contact Form With PayPal: up to and including 1.1.5
Published 2017-09-30. Last modified 2026-06-17.