Wpagecontact Project maintains a narrowly scoped contact-form plugin or similar web application component, with observed vulnerabilities centered on SQL injection in the handling of user-submitted form data. Current vulnerability counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpagecontact Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24403HIGH The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitised, escaped or validated before inserting to a SQL statement | Sep 20, 2021 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpagecontact Project.
Media articles that mention a CVE ID that affects a product developed by Wpagecontact Project — matched by CVE ID, not by vendor name.