CVE-2020-35489: Malicious File Upload
Published Dec 17, 2020
·Updated
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
Affected Software
1 affected component
Rocklobster Contact Form 7 Wordpress<5.3.2
Event History
Dec 17, 2020
CVE Published
via MITRE·06:16 PM
Data Sourced
via MITRE·06:16 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35489?
The severity of CVE-2020-35489 is critical.
2
What is CVE-2020-35489?
CVE-2020-35489 refers to a vulnerability in the contact-form-7 plugin for WordPress that allows unrestricted file upload and remote code execution.
3
What software is affected by CVE-2020-35489?
The contact-form-7 plugin before version 5.3.2 for WordPress is affected by CVE-2020-35489.
4
How can I fix CVE-2020-35489?
To fix CVE-2020-35489, you should update the contact-form-7 plugin to version 5.3.2 or later.
5
What is CWE-434?
CWE-434 refers to a vulnerability that allows an attacker to upload malicious files or overwrite existing files on a target system.