Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-19806
HistoryMar 02, 2022 - 12:00 a.m.

WordPress Drag & Drop Contact Form Plugin Arbitrary File Download Vulnerability

2022-03-0200:00:00
China National Vulnerability Database
www.cnvd.org.cn
20
wordpress
contact form
arbitrary file download
vulnerability
php
special symbols
attack

EPSS

0.001

Percentile

47.6%

WordPress is a blogging platform developed by the Wordpress Foundation using the PHP language. An arbitrary file download vulnerability exists in Wordpress Drag & Drop Contact Form Plugin 1.0.5 and prior versions, which stems from the product’s file download feature not effectively handling special symbols. An attacker could download arbitrary files through this vulnerability.

EPSS

0.001

Percentile

47.6%

Related for CNVD-2022-19806