Cross-Site Scripting
8 records47.1%First: 2014. Latest: 2025.
Plugin security history
The Wordfence Intelligence dataset currently contains 17 vulnerability records associated with Contact Form Email, published between 2014 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2014 | 1 | |
| 2015 | 1 | |
| 2016 | 1 | |
| 2019 | 3 | |
| 2021 | 1 | |
| 2023 | 5 | |
| 2024 | 1 | |
| 2025 | 3 | |
| 2026 | 1 |
| Severity | Records | Share |
|---|---|---|
| High | 5 | 29.4% |
| Medium | 12 | 70.6% |
First: 2014. Latest: 2025.
First: 2023. Latest: 2026.
First: 2015. Latest: 2023.
First: 2023. Latest: 2023.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
1.3.641.3.611.3.591.3.531.3.451.3.421.3.441.3.381.3.321.3.251.2.661.1.481.3.121.0.1Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-1.3.63 | Contact Form Email <= 1.3.63 - Missing Authorization | March 23, 2026 | 1.3.64 | Medium |
*-1.3.60 | Contact Form Email <= 1.3.60 - Unauthenticated Insecure Direct Object Reference | December 1, 2025 | 1.3.61 | Medium |
*-1.3.58 | Contact Form Email <= 1.3.58 - Missing Authorization | November 15, 2025 | 1.3.59 | Medium |
*-1.3.52 | Contact Form Email <= 1.3.52 - Authenticated (Administrator+) Stored Cross-Site Scripting | January 24, 2025 | 1.3.53 | Medium |
*-1.3.44 | Contact Form Email <= 1.3.44 - Unauthenticated Sensitive Information Exposure | April 5, 2024 | 1.3.45 | Medium |
*-1.3.41 | Contact Form Email <= 1.3.41 - Captcha Bypass | November 23, 2023 | 1.3.42 | Medium |
*-1.3.43 | Contact Form Email <= 1.3.43 - Authenticated (Admin+) Stored Cross-Site Scripting | November 14, 2023 | 1.3.44 | Medium |
*-1.3.37 | Contact Form Email <= 1.3.37 - Unauthenticated Stored Cross-Site Scripting | May 16, 2023 | 1.3.38 | High |
*-1.3.31 | Contact Form Email <= 1.3.31 - Cross-Site Request Forgery to Feedback Submission | March 21, 2023 | 1.3.32 | Medium |
*-1.3.31 | Contact Form Email <= 1.3.31 - Missing Authorization to Feedback Submission | March 16, 2023 | 1.3.32 | Medium |
*-1.3.24 | Contact Form Email <= 1.3.24 - Authenticated (Admin+) Stored Cross-Site Scripting | November 11, 2021 | 1.3.25 | Medium |
*-1.2.65 | Contact Form Email <= 1.2.65 - Cross-Site Request Forgery | August 12, 2019 | 1.2.66 | High |
*-1.2.65 | Contact Form Email <= 1.2.65 - Cross-Site Scripting | August 12, 2019 | 1.2.66 | Medium |
[*, 1.2.66) | Contact Form Email <= 1.2.65 - Reflected Cross-Site Scripting | February 5, 2019 | 1.2.66 | Medium |
[*, 1.1.48) | Contact Form Email < 1.1.48 - Reflected Cross-Site Scripting | July 24, 2016 | 1.1.48 | High |
[*, 1.3.12) | Contact Form Email <= 1.3.11 - Cross-Site Request Forgery to Cross-Site Scripting | May 13, 2015 | 1.3.12 | High |
[*, 1.0.1) | Contact Form Email < 1.0.1 - Cross-Site Scripting | November 22, 2014 | 1.0.1 | High |
Selected source records
Published: March 23, 2026
Published: December 1, 2025
Published: November 15, 2025
Published: January 24, 2025
Published: April 5, 2024
Published: November 23, 2023
Published: November 14, 2023
Published: May 16, 2023
Published: August 12, 2019
Published: May 13, 2015
Published: May 16, 2023
Published: November 22, 2014
Published: July 24, 2016
Published: February 5, 2019
Published: August 12, 2019
Published: April 5, 2024
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.