ThinkIT WP Contact Form

ThinkIT WP Contact Form has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2013; all 2 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.1 out of 10. 2013 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.

Every one of the 2 issues recorded for ThinkIT WP Contact Form has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by Yashar Shahinzadeh. ThinkIT WP Contact Form is installed on roughly 20 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 0.

Strategic Overview

Avg CVSSMedium
5.4/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all ThinkIT WP Contact Form vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1

ThinkIT WP Contact Form Plugin < 0.3 - Cross-Site Scripting

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv0.1

ThinkIT WP Contact Form

Pandurang Zambare

Author

Pandurang Zambare

5.0(3)
100/100
Last Updated
2014-07-24 (12y ago)
Active Installs
20+
Downloads
3,867
Requires WP
3.4+
Requires PHP
0+
Tested up to
WP 0
Created
2012-09-11 (14y ago)

A very simple, easy to use, customizable and light weight contact form plugin for WordPress. Supports AJAX form submission if JQUERY plugin is enabled in WORDPRESS. Use it as contact form on your website &#8216;Contact’ page or customize and add as an inquiry / information form anywhere on WordPress sites. Visit developer site at http://thinkoverit.com Remove plugin Deactivate plugin through the &#8216;Plugins’ menu in WordPress. If you wish to completely remove the plugin, you may delete the respective plugin folder through the &#8216;Plugins’ menu in WordPress It’s best to use the build in delete function of wordpress. That way all the stored data will be removed and no orphaned data will stay. How can I support you? You can link back to our site at http://thinkOverIT.com . We will take it as an appreciation and love for our plugin. What is the plugin page? http://thinkoverit.com/ThinkIT-WP-Contact-Form-Plugin/ Where do I post my feedback? Post it at the plugin post: http://thinkoverit.com/ThinkIT-WP-Contact-Form-Plugin/

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C