Description
WordPress Plugin Contact Form Email is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Contact Form Email version 1.2.66 is vulnerable; prior versions may also be affected.
Remediation
Disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin Data Tables Generator by Supsystic Multiple Vulnerabilities (1.9.91)
Coppermine Cross-site Scripting (XSS) Vulnerability (CVE-2015-3921)
Oracle Database Server Other Vulnerability (CVE-2003-0727)
WordPress Plugin Facebook Promotion Generator for WordPress 'fbActivate.php' SQL Injection (1.3.3)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3385)