WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Constant Contact Forms

The official Constant Contact plugin adds a contact form to your WordPress site to quickly capture information from visitors.

4Reported vulnerabilities
5.3Highest CVSS score
2.21.0Latest version
20,000+Active installs

What to do now

Update Constant Contact Forms to 2.4.3 or later. 4 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 6, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2021-24134 Medium 4.8 0.7% Before 1.8.8 1.8.8 March 18, 2021
CVE-2023-52208 Medium 5.3 0.4% 2.4.2 and earlier 2.4.3 January 3, 2024
WF-b8a26695-4793-418b-9a23-6709fe79ea4f Medium 4.3 2.0.2 and earlier 2.0.3 June 15, 2023
CVE-2023-34387 Medium 4.3 0.5% 1.14.0 and earlier 2.0.0 June 3, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.