Medium severity5.4NVD Advisory· Published Aug 9, 2019· Updated Jun 17, 2026
CVE-2019-14785
CVE-2019-14785
Description
The "CP Contact Form with PayPal" plugin before 1.2.99 for WordPress has XSS in the publishing wizard via the wp-admin/admin.php?page=cp_contact_form_paypal.php&pwizard=1 cp_contactformpp_id parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:codepeople:cp_contact_form_with_paypal:*:*:*:*:*:wordpress:*:*Range: <1.2.99
- Range: <1.2.99
Patches
Vulnerability mechanics
References
2- www.pluginvulnerabilities.com/2019/06/24/reflected-cross-site-scripting-xss-vulnerability-in-cp-contact-form-with-paypal/nvdExploitThird Party Advisory
- wordpress.org/plugins/cp-contact-form-with-paypal/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.