Vulnerability Bulletins

Arbitrary File Upload Vulnerability in All Post Contact Form


System information

   
Affected software Wordpress

Description

https://www.pluginvulnerabilities.com/2017/09/20/arbitrary-file-upload-vulnerability-in-all-post-contact-form/Through the proactive monitoring of changes in WordPress plugins for serious vulnerabilities we do, we recently found an an arbitrary file upload vulnerability in the All Post Contact Form plugin. When the plugins shortcode, rlallpostcontactform, is on a post or page the the file /allpost-contactform-core.php is included. In that file the following code is run: 53 […]

More info:

https://www.pluginvulnerabilities.com/2017/09/20/arbitrary-file-upload-vulnerability-in-all-post-contact-form/

Standar resources

Property Value
CVE

Version history

Version Comments Date
1.0 Advisory issued 2017-09-21
Ministerio de Defensa
CNI
CCN
CCN-CERT