CVE-2019-9646: Codepeople Contact Form Email
Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.
The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_edition.inc.php in the "custom edition area."
Affected products
- Codepeople Contact Form Email: before 1.2.66 (fixed in 1.2.66)
Published 2019-03-10. Last modified 2026-06-17.