CVE-2020-12800: Malicious File Upload
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supportedtype to php% and uploading a .php% file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12800?
CVE-2020-12800 is a vulnerability in the drag-and-drop-multiple-file-upload-contact-form-7 plugin for WordPress that allows unrestricted file upload and remote code execution.
How severe is CVE-2020-12800?
CVE-2020-12800 has a severity rating of 9.8, which is considered critical.
How does CVE-2020-12800 work?
CVE-2020-12800 works by allowing an attacker to set the supported_type parameter to 'php%' and upload a .php% file, which can lead to unrestricted file upload and remote code execution.
What software is affected by CVE-2020-12800?
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before version 1.3.3.3 for WordPress is affected by CVE-2020-12800.
Is there a fix for CVE-2020-12800?
Yes, the fix for CVE-2020-12800 is to update the drag-and-drop-multiple-file-upload-contact-form-7 plugin to version 1.3.3.3 or later.