PT-2026-69376 · WordPress · Contact Form To Any Api
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Contact Form to Any API versions prior to 3.0.7
Description
The plugin fails to use random filenames when copying files uploaded via contact forms into a publicly accessible directory. This allows unauthenticated attackers to enumerate and download files submitted by other users.
Recommendations
Update to version 3.0.7 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contact Form To Any Api