Input validation vulnerability in Contact Form 7 5.8.3

The Contact Form 7 plugin for WordPress, which is used to create contact forms for websites, has a security issue in versions up to 5.8.3. This vulnerability allows attackers who have editor-level access or higher to upload any type of file to the website’s server. Normally, the file would be deleted right away, but some other plugins could cause it to stay on the server and possibly be used to execute remote code if combined with another vulnerability such as local file inclusion.

Detected in:

Contact Form 7 fixed vulnerable versions: >= * <= 5.8.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.