CVE-2020-35489
EUVD-2020-2316017.12.2020, 19:15
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| rocklobster | contact_form_7 | 𝑥 < 5.3.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References