WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Contact Form Email

Contact form with visual form builder. Contact form that sends the data to email, to a database list and to CSV / Excel files.

14Reported vulnerabilities
8.8Highest CVSS score
1.3.68Latest version
8,000+Active installs

What to do now

Update Contact Form Email to 1.3.64 or later. 14 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 17, 2026 / Tested up to WordPress: 7.1 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2019-9646 Medium 6.1 1.4% Before 1.2.66 1.2.66 March 10, 2019
CVE-2018-20964 High 8.8 0.7% Before 1.2.66 1.2.66 August 13, 2019
WF-fa9450a4-2b96-45e4-b2dc-9a4b26449d19 High 8.8 Before 1.3.12 1.3.12 May 13, 2015
WF-c77295f3-0a37-4fa8-a375-b4bd3dc55945 High 7.1 Before 1.1.48 1.1.48 July 24, 2016
WF-a0850b88-09f0-4da8-a9be-1b4aacf610e0 High 7.2 Before 1.0.1 1.0.1 November 22, 2014
CVE-2018-20963 Medium 6.1 0.9% Before 1.2.66 1.2.66 August 13, 2019
CVE-2025-10019 Medium 5.3 0.4% 1.3.60 and earlier 1.3.61 December 1, 2025
CVE-2024-31302 Medium 5.3 0.5% 1.3.44 and earlier 1.3.45 April 5, 2024
CVE-2023-48318 Medium 5.3 0.3% 1.3.41 and earlier 1.3.42 November 23, 2023
CVE-2025-24727 Medium 4.4 0.3% 1.3.52 and earlier 1.3.53 January 24, 2025
CVE-2026-32483 Medium 4.3 0.3% 1.3.63 and earlier 1.3.64 March 23, 2026
CVE-2025-64369 Medium 4.3 0.2% 1.3.58 and earlier 1.3.59 November 15, 2025
WF-ce6ea115-941e-482f-a2a4-95293ff10a69 Medium 4.3 1.3.31 and earlier 1.3.32 March 21, 2023
CVE-2023-28494 Medium 4.3 0.3% 1.3.31 and earlier 1.3.32 March 16, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.