Cross-Site Request Forgery in Contact Form to Email Plugin for WordPress
CVE-2018-20964
8.8HIGH
What is CVE-2018-20964?
The Contact Form to Email plugin for WordPress prior to version 1.2.66 is vulnerable to Cross-Site Request Forgery (CSRF). This vulnerability may allow an attacker to perform actions on behalf of an authenticated user without their consent, leading to potential unauthorized access and manipulation of user data. It is crucial for users of the affected plugin to update to the latest version to mitigate risks associated with this vulnerability.