CVE-2026-32433
WordPress CP Contact Form with Paypal plugin <= 1.3.61 - SQL Injection vulnerability
CVSS Score
8.5
EPSS Score
0.0%
EPSS Percentile
10th
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in codepeople CP Contact Form with Paypal cp-contact-form-with-paypal allows Blind SQL Injection.This issue affects CP Contact Form with Paypal: from n/a through <= 1.3.61.
| CWE | CWE-89 |
| Vendor | codepeople |
| Product | cp contact form with paypal |
| Published | Mar 13, 2026 |
| Last Updated | Apr 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for codepeople cp contact form with paypal
Be the first to know when new high vulnerabilities affecting codepeople cp contact form with paypal are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
codepeople / CP Contact Form with Paypal
0 โค 1.3.61
References
Credits
Nguyen Ba Khanh | Patchstack Bug Bounty Program