Vulnerabilities and security researches forcustom-contact-forms custom-contact-forms
Direction: ascendingJun 07, 2024
Custom Contact Forms # 8d40a27aa2a01e701a41665acc39c031f225fdaf
- CVE, Research URL
- Home page URL
- Application
- Date
- May 15, 2015
- Research Description
- Custom Contact Forms [custom-contact-forms] < 5.1.0.4 (closed) WordPress Custom Contact Forms Plugin <= 5.1.0.3 - Database Import/Export This plugin is prone to a database import/export vulnerabilities. Update the plugin.
- Affected versions
-
max 5.1.0.4.
- Status
-
vulnerable
Jun 16, 2026
Custom Contact Forms # 2765cc28b6069975626b406a82a133a70ed056b2
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 17, 2014
- Research Description
- Custom Contact Forms [custom-contact-forms] < 5.1.0.4 (closed) Custom Contact Forms <= 5.1.0.3 - Missing Authorization The Custom Contact Forms plugin for WordPress is vulnerable to authentication bypass due to missing capability checks on admin_init() function called via an 'init' hook in versions before 5.1.0.4. This makes it possible for unauthenticated attackers to download and modify the database of the affected site.
- Affected versions
-
max 5.1.0.4.
- Status
-
vulnerable
Custom Contact Forms # a4c946b5b30b22809297deb704433f75ba49eac6
- CVE, Research URL
- Home page URL
- Application
- Date
- May 11, 2012
- Research Description
- Custom Contact Forms [custom-contact-forms] < 5.1.0.3 (closed) Custom Contact Forms Plugin <= 5.1.0.2 - Reflected Cross-Site Scripting The Custom Contact Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via an arbitrarily supplied parameter in versions up to, and including, 5.1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 5.1.0.3.
- Status
-
vulnerable
Custom Contact Forms # d1986540-1161-4972-9fae-76c07546a21a
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Custom Contact Forms [custom-contact-forms] < 5.1.0.4 (closed) Custom Contact Forms < 5.1.0.4 - Unauthenticated Database Import/Export The Custom Contact Forms WordPress plugin was vulnerable to a critical vulnerability that allowed an attacker to download and modify the database remotely without authentication.
- Affected versions
-
max 5.1.0.4.
- Status
-
vulnerable
Custom Contact Forms # 5c387ec5-a3a5-4a31-9fed-4f7930b9d5dc
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Custom Contact Forms [custom-contact-forms] < 5.1.0.3 (closed) Custom Contact Forms < 5.1.0.3 - Authenticated Cross Site Scripting The Custom Contact Forms WordPress plugin was affected by an Authenticated Cross Site Scripting security vulnerability.
- Affected versions
-
max 5.1.0.3.
- Status
-
vulnerable
Custom Contact Forms # bf046bdf4f5bbd34f3a17f2b7b80d27b340760ae
- CVE, Research URL
- Home page URL
- Application
- Date
- May 15, 2023
- Research Description
- Custom Contact Forms [custom-contact-forms] < 5.1.0.4 (closed) WordPress Custom Contact Forms Plugin <= 5.1.0.3 is vulnerable to Bypass Vulnerability Update the plugin. An unknown person discovered and reported this Bypass Vulnerability vulnerability in WordPress Custom Contact Forms Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has been fixed in version 5.1.0.4.
- Affected versions
-
max 5.1.0.4.
- Status
-
vulnerable
Custom Contact Forms # f3eca5341708368a105f210125856e74fbd548e7
- CVE, Research URL
- Home page URL
- Application
- Date
- May 15, 2015
- Research Description
- Custom Contact Forms [custom-contact-forms] < 5.0.0.2 (closed) WordPress Custom Contact Forms Plugin <= 5.0.0.1 - XSS Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
- Affected versions
-
max 5.0.0.2.
- Status
-
vulnerable
Custom Contact Forms # 39122f897433b6ec036186d3c378d3e28b55c3fb
- CVE, Research URL
- Home page URL
- Application
- Date
- May 15, 2023
- Research Description
- Custom Contact Forms [custom-contact-forms] < 5.0.0.2 (closed) WordPress Custom Contact Forms Plugin <= 5.0.0.1 is vulnerable to Cross Site Scripting (XSS) Update the plugin. An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Custom Contact Forms Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 5.0.0.2.
- Affected versions
-
max 5.0.0.2.
- Status
-
vulnerable
Sep 06, 2026
Custom Contact Forms # CVE-2026-75018
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 05, 2026
- Research Description
- The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to permanently force-delete arbitrary posts of any post type (including pages, administrator-authored posts, and WooCommerce products) and write arbitrary ccf_field_* post meta onto any post regardless of ownership or post type. The top-level form ID is checked via edit_post/publish_posts, but the nested fields[].ID and choices[].ID paths processed by _create_and_map_fields() and _create_and_map_choices() carry no equivalent capability or post-type guard, leaving those sinks fully exposed while delete_item() and delete_submission() contain explicit post-type restriction fixes demonstrating the developer's awareness of scoping requirements.
- Affected versions
-
max 7.16.1.
- Status
-
vulnerable