CVE-2025-10019
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-10019 is an Insecure Direct Object Reference (IDOR) / Authorization Bypass Through User-Controlled Key vulnerability in the Contact Form Email WordPress plugin by CodePeople. It affects all versions up to and including 1.3.60, allowing unauthenticated attackers to bypass access controls and interact with protected resources. The vulnerability was reported by researcher "Rooting" on September 24, 2025, published by Patchstack on December 1, 2025, and assigned a CVE on December 18, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).

Technical details

The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), which maps to OWASP Top 10 A1: Broken Access Control. The plugin fails to properly validate or authorize user-supplied object references, enabling an unauthenticated attacker to manipulate request parameters to access or interact with objects (e.g., form submissions, configuration data) they should not be permitted to reach. No authentication or user interaction is required for exploitation, and attack complexity is low, making it straightforward to abuse over the network (Patchstack).

Impact

Successful exploitation can result in unauthorized access to sensitive data (e.g., form submission contents, contact information) and unauthorized modification of plugin-managed data, yielding low confidentiality and low integrity impacts with no direct availability impact. Because the plugin is used to handle contact form submissions on WordPress sites, exposed data may include personally identifiable information (PII) submitted by site visitors. Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously, regardless of site size or traffic (Patchstack).

Exploitability

No public proof-of-concept exploit code has been identified at this time. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as "expected to become exploited" and notes that IDOR vulnerabilities in WordPress plugins are commonly leveraged in automated mass-exploit campaigns (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Contact Form Email plugin (versions ≤ 1.3.60) using tools like WPScan, Shodan, or by inspecting plugin directories (/wp-content/plugins/contact-form-to-email/).
  2. Identify target endpoints: Locate plugin-specific endpoints or AJAX actions that accept object reference parameters (e.g., form IDs, submission IDs) without enforcing authorization checks.
  3. Manipulate object references: Submit unauthenticated HTTP requests to the vulnerable endpoint, modifying the user-controlled key parameter (e.g., incrementing or enumerating form/submission IDs) to reference objects belonging to other users or restricted contexts.
  4. Access or modify unauthorized data: Retrieve sensitive form submission data (e.g., contact details, PII) or alter plugin configuration objects that should be restricted to administrators, achieving the attacker's objective without any valid credentials (Patchstack).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP GET or POST requests to WordPress AJAX endpoints (/wp-admin/admin-ajax.php) or plugin-specific URLs with enumerated or manipulated ID parameters associated with the contact-form-to-email plugin.
  • Logs: WordPress access logs showing repeated requests to plugin endpoints with sequentially varying object reference parameters (e.g., form_id=1, form_id=2, ...) from a single IP or user agent, particularly without a valid session cookie.
  • File System: No direct file system artifacts expected for IDOR exploitation; however, unexpected changes to plugin configuration files in /wp-content/plugins/contact-form-to-email/ may indicate post-exploitation tampering.

Mitigation and workarounds

The vendor has released a patched version: Contact Form Email 1.3.61. All site administrators running version 1.3.60 or earlier should update immediately via the WordPress plugin dashboard or by downloading the latest version from the WordPress plugin repository. Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated. If an immediate update is not possible, consider temporarily deactivating the plugin or consulting your hosting provider (Patchstack).

Community reactions

The vulnerability was covered in Wordfence's weekly WordPress vulnerability report for the week of December 1–7, 2025, and was included in a CISA vulnerability summary for the week of December 15, 2025, aggregated by Red Packet Security. No significant independent researcher commentary or broader media coverage has been identified beyond these routine security digest mentions.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19848MEDIUM6.5
  • wp-user-avatar
NoYesAug 21, 2026
CVE-2026-17559MEDIUM5.3
  • content-protector
NoYesAug 21, 2026
CVE-2026-16650MEDIUM5.3
  • charitable
NoYesAug 21, 2026
CVE-2026-15150MEDIUM5.3
  • mycred
NoYesAug 21, 2026
CVE-2026-18356LOW3.7
  • limit-login-attempts-reloaded
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management