Vulnerability Description
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rocklobster | Contact Form 7 | < 5.3.2 |
Related Weaknesses (CWE)
References
- https://contactform7.com/2020/12/17/contact-form-7-532/Vendor Advisory
- https://wordpress.org/plugins/contact-form-7/#developersRelease NotesThird Party Advisory
- https://wpscan.com/vulnerability/10508Third Party Advisory
- https://www.getastra.com/blog/911/plugin-exploit/contact-form-7-unrestricted-filThird Party Advisory
- https://www.jinsonvarghese.com/unrestricted-file-upload-in-contact-form-7/Third Party Advisory
- https://contactform7.com/2020/12/17/contact-form-7-532/Vendor Advisory
- https://wordpress.org/plugins/contact-form-7/#developersRelease NotesThird Party Advisory
- https://wpscan.com/vulnerability/10508Third Party Advisory
- https://www.getastra.com/blog/911/plugin-exploit/contact-form-7-unrestricted-filThird Party Advisory
- https://www.jinsonvarghese.com/unrestricted-file-upload-in-contact-form-7/Third Party Advisory
FAQ
What is CVE-2020-35489?
CVE-2020-35489 is a vulnerability with a CVSS score of 10.0 (CRITICAL). The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
How severe is CVE-2020-35489?
CVE-2020-35489 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-35489?
Check the references section above for vendor advisories and patch information. Affected products include: Rocklobster Contact Form 7.