First published: Mon Feb 28 2022(Updated: )
The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin through 1.0.5 allows high privilege users to download arbitrary files from the web server via a path traversal attack
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPEverest Contact Form | <=1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Contact Forms - Drag & Drop Contact Form Builder WordPress plugin is CVE-2021-24689.
The severity of CVE-2021-24689 is medium with a severity value of 4.9.
CVE-2021-24689 allows high privilege users to download arbitrary files from the web server via a path traversal attack.
The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin versions up to and including 1.0.5 are affected by CVE-2021-24689.
Yes, you can find more information about CVE-2021-24689 at the following reference: [link](https://wpscan.com/vulnerability/31824250-e0d4-4285-97fa-9880b363e075).