First published: Thu Aug 22 2019(Updated: )
The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rocklobster Contact Form 7 | <5.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20979 is a vulnerability in the contact-form-7 plugin for WordPress that allows privilege escalation due to capability_type mishandling in register_post_type.
CVE-2018-20979 is classified as critical with a severity score of 9.8 out of 10.
The contact-form-7 plugin versions up to and excluding 5.0.4 are affected by CVE-2018-20979.
The vendor of the contact-form-7 plugin is Rocklobster.
To fix CVE-2018-20979, it is recommended to update the contact-form-7 plugin to version 5.0.4 or later.