Vulnerability Bulletins

Uncovering Potential Issues with the Contact Form 7 Vulnerability: More Data Needed


System information

   
Affected software Wordpress

Description

On December 17, 2020, the Astra research security team disclosed that they had discovered a critical severity Unrestricted File Upload vulnerability in Contact Form 7, the most popular WordPress plugin of all time. The lead researcher, Jinson Varghese, also published a blog post providing limited information about this vulnerability. The initial disclosure claimed that “By […]

More info:

https://www.wordfence.com/blog/2021/01/uncovering-potential-issues-with-the-contact-form-7-vulnerability-more-data-needed/

Standar resources

Property Value
CVE MILW0RM/4929.

Version history

Version Comments Date
1.0 Advisory issued 2021-01-20
Ministerio de Defensa
CNI
CCN
CCN-CERT