QID 730094

Date Published: 2021-11-17

QID 730094: WordPress Contact Form Unrestricted File-Upload and Remote Code Execution (RCE) Vulnerability

WordPress is an open-source blogging tool and content management system based on PHP and MySQL. It has many features including a plug-in architecture and a template system. The " CFDB" plugin saves contact form submissions to your WordPress database and provides an administration page and shortcodes to view and display the data.

CVE-2020-35489 - The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.

Affected Versions:
The Contact-Form-7 plugin versions before 5.3.2 for WordPress

QID Detection Logic:(Unauthenticated)
It checks for the vulnerable version of the plugin.

Successful exploitation could allow unrestricted file upload and remote code execution.

  • CVSS V3 rated as Critical - 10 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to install Contact Form plugin version 7 5.3.2 or later versions to remediate this vulnerability.
    Vendor References

    CVEs related to QID 730094

    Software Advisories
    Advisory ID Software Component Link
    Contact Form 7 5.3.2 URL Logo contactform7.com/2020/12/17/contact-form-7-532/#more-38314