VYPR

Contact Form

by WordPress

Source repositories

CVEs (22)

  • CVE-2026-14236MedJul 27, 2026
    risk 0.00cvss 4.7epss 0.00

    The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it as the success and cancel redirect targets of a Stripe checkout, allowing an unauthenticated attacker to redirect a victim, via a crafted link, to an…

  • CVE-2014-2265Mar 14, 2014
    risk 0.00cvss epss 0.03

    Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 parameter.

Page 2 of 2