First published: Thu Dec 17 2020(Updated: )
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rocklobster Contact Form 7 | <5.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-35489 is critical.
CVE-2020-35489 refers to a vulnerability in the contact-form-7 plugin for WordPress that allows unrestricted file upload and remote code execution.
The contact-form-7 plugin before version 5.3.2 for WordPress is affected by CVE-2020-35489.
To fix CVE-2020-35489, you should update the contact-form-7 plugin to version 5.3.2 or later.
CWE-434 refers to a vulnerability that allows an attacker to upload malicious files or overwrite existing files on a target system.