WordPress Contact Form 7 Plugin Security Bypass Vulnerability
BID:66381
Info
WordPress Contact Form 7 Plugin Security Bypass Vulnerability
| Bugtraq ID: | 66381 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2265 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2014 12:00AM |
| Updated: | Feb 26 2014 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
WordPress WordPress 0 |
| Not Vulnerable: | |
Discussion
WordPress Contact Form 7 Plugin Security Bypass Vulnerability
The Contact Form 7 plugin for WordPress is prone to a security-bypass vulnerability.
Attackers can leverage this issue to bypass security restrictions and perform unauthorized actions; this may aid in launching further attacks.
Versions prior to Contact Form 7 3.7.2 are vulnerable.
The Contact Form 7 plugin for WordPress is prone to a security-bypass vulnerability.
Attackers can leverage this issue to bypass security restrictions and perform unauthorized actions; this may aid in launching further attacks.
Versions prior to Contact Form 7 3.7.2 are vulnerable.
Exploit / POC
WordPress Contact Form 7 Plugin Security Bypass Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
WordPress Contact Form 7 Plugin Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.