CVE-2020-35489 Information

Description

The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Reference

https://www.getastra.com/blog/911/plugin-exploit/contact-form-7-unrestricted-file-upload/ https://wordpress.org/plugins/contact-form-7/#developers https://www.jinsonvarghese.com/unrestricted-file-upload-in-contact-form-7/ https://contactform7.com/2020/12/17/contact-form-7-532/ https://wpscan.com/vulnerability/10508

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

CHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

10.0

Share on: