VYPR

wpagecontact

by WordPress

CVEs (1)

  • CVE-2021-24403Sep 20, 2021
    risk 0.00cvss epss 0.01

    The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributors