CVE-2018-20979: Critical severity rocklobster contact form 7 vulnerability
Published Aug 22, 2019
·Updated
The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capabilitytype mishandling in registerposttype.
Affected Software
1 affected component
Rocklobster Contact Form 7 Wordpress<5.0.4
Event History
Aug 22, 2019
CVE Published
via MITRE·12:36 PM
Data Sourced
via MITRE·12:36 PM
Description
Frequently Asked Questions
1
What is CVE-2018-20979?
CVE-2018-20979 is a vulnerability in the contact-form-7 plugin for WordPress that allows privilege escalation due to capability_type mishandling in register_post_type.
2
How severe is CVE-2018-20979?
CVE-2018-20979 is classified as critical with a severity score of 9.8 out of 10.
3
Which version of the contact-form-7 plugin is affected by CVE-2018-20979?
The contact-form-7 plugin versions up to and excluding 5.0.4 are affected by CVE-2018-20979.
4
Who is the vendor of the contact-form-7 plugin?
The vendor of the contact-form-7 plugin is Rocklobster.
5
How can I fix CVE-2018-20979?
To fix CVE-2018-20979, it is recommended to update the contact-form-7 plugin to version 5.0.4 or later.