CVE-2021-24689: Contact Forms - Drag & Drop Contact Form Builder <= 1.0.5 - Admin+ Arbitrary System File Read
The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin through 1.0.5 allows high privilege users to download arbitrary files from the web server via a path traversal attack
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Contact Forms - Drag & Drop Contact Form Builder WordPress plugin?
The vulnerability ID for the Contact Forms - Drag & Drop Contact Form Builder WordPress plugin is CVE-2021-24689.
What is the severity of CVE-2021-24689?
The severity of CVE-2021-24689 is medium with a severity value of 4.9.
How does CVE-2021-24689 affect the Contact Forms - Drag & Drop Contact Form Builder WordPress plugin?
CVE-2021-24689 allows high privilege users to download arbitrary files from the web server via a path traversal attack.
What software versions are affected by CVE-2021-24689?
The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin versions up to and including 1.0.5 are affected by CVE-2021-24689.
Is there a reference for CVE-2021-24689?
Yes, you can find more information about CVE-2021-24689 at the following reference: [link](https://wpscan.com/vulnerability/31824250-e0d4-4285-97fa-9880b363e075).