CVE-2024-5808: Masdiblogs Wp AJAX Contact Form
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The WP Ajax Contact Form WordPress plugin through 2.2.2 does not have CSRF check in place when deleting emails from the email list, which could allow attackers to make a logged in admin perform such action via a CSRF attack
Affected products
- Masdiblogs Wp AJAX Contact Form: up to and including 2.2.2
Published 2024-07-30. Last modified 2026-06-17.