QID 154132

Date Published: 2023-03-21

QID 154132: WordPress Contact Form 7 Plugin: Unrestricted File Upload and Remote Code Execution (RCE) Vulnerability (CVE-2020-35489)

Contact Form 7 is a WordPress plugin which allows users to customize, manage multiple contact forms along with mail facility.

Affected versions of Contact Form 7 allows Unrestricted File Upload and remote code execution if a filename contains special characters.

Affected Versions:
Contact Form 7 prior to version 5.3.2

QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of Contact Form 7 plugin running on the target application.

Successful exploitation of this vulnerability could allow an attacker to upload malicious file and execute arbitrary code on the target system.

  • CVSS V3 rated as Critical - 10 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade to version 5.3.2 or later to remediate this vulnerability. For more information regarding this vulnerability please refer Contact Form 7 .
    Vendor References

    CVEs related to QID 154132

    Software Advisories
    Advisory ID Software Component Link
    Contact Form 7 5.3.2 URL Logo contactform7.com/2020/12/17/contact-form-7-532/