cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcustom-contact-forms custom-contact-forms

Direction: ascending
Jun 07, 2024

Custom Contact Forms # 8d40a27aa2a01e701a41665acc39c031f225fdaf

Application

Custom Contact Forms

Date
May 15, 2015
Research Description
Custom Contact Forms [custom-contact-forms] < 5.1.0.4 (closed) WordPress Custom Contact Forms Plugin <= 5.1.0.3 - Database Import/Export This plugin is prone to a database import/export vulnerabilities. Update the plugin.
Affected versions
max 5.1.0.4.
Status
vulnerable
Jun 16, 2026

Custom Contact Forms # 2765cc28b6069975626b406a82a133a70ed056b2

Application

Custom Contact Forms

Date
Sep 17, 2014
Research Description
Custom Contact Forms [custom-contact-forms] < 5.1.0.4 (closed) Custom Contact Forms <= 5.1.0.3 - Missing Authorization The Custom Contact Forms plugin for WordPress is vulnerable to authentication bypass due to missing capability checks on admin_init() function called via an 'init' hook in versions before 5.1.0.4. This makes it possible for unauthenticated attackers to download and modify the database of the affected site.
Affected versions
max 5.1.0.4.
Status
vulnerable

Custom Contact Forms # a4c946b5b30b22809297deb704433f75ba49eac6

Application

Custom Contact Forms

Date
May 11, 2012
Research Description
Custom Contact Forms [custom-contact-forms] < 5.1.0.3 (closed) Custom Contact Forms Plugin <= 5.1.0.2 - Reflected Cross-Site Scripting The Custom Contact Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an arbitrarily supplied parameter in versions up to, and including, 5.1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 5.1.0.3.
Status
vulnerable

Custom Contact Forms # d1986540-1161-4972-9fae-76c07546a21a

Application

Custom Contact Forms

Date
-
Research Description
Custom Contact Forms [custom-contact-forms] < 5.1.0.4 (closed) Custom Contact Forms &lt; 5.1.0.4 - Unauthenticated Database Import/Export The Custom Contact Forms WordPress plugin was vulnerable to a critical vulnerability that allowed an attacker to download and modify the database remotely without authentication.
Affected versions
max 5.1.0.4.
Status
vulnerable

Custom Contact Forms # 5c387ec5-a3a5-4a31-9fed-4f7930b9d5dc

Application

Custom Contact Forms

Date
-
Research Description
Custom Contact Forms [custom-contact-forms] < 5.1.0.3 (closed) Custom Contact Forms &lt; 5.1.0.3 - Authenticated Cross Site Scripting The Custom Contact Forms WordPress plugin was affected by an Authenticated Cross Site Scripting security vulnerability.
Affected versions
max 5.1.0.3.
Status
vulnerable

Custom Contact Forms # bf046bdf4f5bbd34f3a17f2b7b80d27b340760ae

Application

Custom Contact Forms

Date
May 15, 2023
Research Description
Custom Contact Forms [custom-contact-forms] < 5.1.0.4 (closed) WordPress Custom Contact Forms Plugin <= 5.1.0.3 is vulnerable to Bypass Vulnerability Update the plugin. An unknown person discovered and reported this Bypass Vulnerability vulnerability in WordPress Custom Contact Forms Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has been fixed in version 5.1.0.4.
Affected versions
max 5.1.0.4.
Status
vulnerable

Custom Contact Forms # f3eca5341708368a105f210125856e74fbd548e7

Application

Custom Contact Forms

Date
May 15, 2015
Research Description
Custom Contact Forms [custom-contact-forms] < 5.0.0.2 (closed) WordPress Custom Contact Forms Plugin <= 5.0.0.1 - XSS Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
Affected versions
max 5.0.0.2.
Status
vulnerable

Custom Contact Forms # 39122f897433b6ec036186d3c378d3e28b55c3fb

Application

Custom Contact Forms

Date
May 15, 2023
Research Description
Custom Contact Forms [custom-contact-forms] < 5.0.0.2 (closed) WordPress Custom Contact Forms Plugin <= 5.0.0.1 is vulnerable to Cross Site Scripting (XSS) Update the plugin. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Custom Contact Forms Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 5.0.0.2.
Affected versions
max 5.0.0.2.
Status
vulnerable
Sep 06, 2026

Custom Contact Forms # CVE-2026-75018

CVE, Research URL

CVE-2026-75018

Application

Custom Contact Forms

Date
Sep 05, 2026
Research Description
The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to permanently force-delete arbitrary posts of any post type (including pages, administrator-authored posts, and WooCommerce products) and write arbitrary ccf_field_* post meta onto any post regardless of ownership or post type. The top-level form ID is checked via edit_post/publish_posts, but the nested fields[].ID and choices[].ID paths processed by _create_and_map_fields() and _create_and_map_choices() carry no equivalent capability or post-type guard, leaving those sinks fully exposed while delete_item() and delete_submission() contain explicit post-type restriction fixes demonstrating the developer's awareness of scoping requirements.
Affected versions
max 7.16.1.
Status
vulnerable