CVE-2019-9646: Codepeople Contact Form Email

Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.

The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area."

Affected products

  • Codepeople Contact Form Email: before 1.2.66 (fixed in 1.2.66)

Published 2019-03-10. Last modified 2026-06-17.