
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-10019 is an Insecure Direct Object Reference (IDOR) / Authorization Bypass Through User-Controlled Key vulnerability in the Contact Form Email WordPress plugin by CodePeople. It affects all versions up to and including 1.3.60, allowing unauthenticated attackers to bypass access controls and interact with protected resources. The vulnerability was reported by researcher "Rooting" on September 24, 2025, published by Patchstack on December 1, 2025, and assigned a CVE on December 18, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium) (Patchstack).
The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), which maps to OWASP Top 10 A1: Broken Access Control. The plugin fails to properly validate or authorize user-supplied object references, enabling an unauthenticated attacker to manipulate request parameters to access or interact with objects (e.g., form submissions, configuration data) they should not be permitted to reach. No authentication or user interaction is required for exploitation, and attack complexity is low, making it straightforward to abuse over the network (Patchstack).
Successful exploitation can result in unauthorized access to sensitive data (e.g., form submission contents, contact information) and unauthorized modification of plugin-managed data, yielding low confidentiality and low integrity impacts with no direct availability impact. Because the plugin is used to handle contact form submissions on WordPress sites, exposed data may include personally identifiable information (PII) submitted by site visitors. Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously, regardless of site size or traffic (Patchstack).
No public proof-of-concept exploit code has been identified at this time. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as "expected to become exploited" and notes that IDOR vulnerabilities in WordPress plugins are commonly leveraged in automated mass-exploit campaigns (Patchstack).
/wp-content/plugins/contact-form-to-email/)./wp-admin/admin-ajax.php) or plugin-specific URLs with enumerated or manipulated ID parameters associated with the contact-form-to-email plugin.form_id=1, form_id=2, ...) from a single IP or user agent, particularly without a valid session cookie./wp-content/plugins/contact-form-to-email/ may indicate post-exploitation tampering.The vendor has released a patched version: Contact Form Email 1.3.61. All site administrators running version 1.3.60 or earlier should update immediately via the WordPress plugin dashboard or by downloading the latest version from the WordPress plugin repository. Patchstack users benefit from a virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated. If an immediate update is not possible, consider temporarily deactivating the plugin or consulting your hosting provider (Patchstack).
The vulnerability was covered in Wordfence's weekly WordPress vulnerability report for the week of December 1–7, 2025, and was included in a CISA vulnerability summary for the week of December 15, 2025, aggregated by Red Packet Security. No significant independent researcher commentary or broader media coverage has been identified beyond these routine security digest mentions.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."