Lucene search

K
cvelistMitreCVELIST:CVE-2020-35489
HistoryDec 17, 2020 - 6:16 p.m.

CVE-2020-35489

2020-12-1718:16:00
mitre
www.cve.org
8
cve-2020-35489
contact form 7
wordpress
remote code execution
special characters
security vulnerability

AI Score

9.9

Confidence

High

EPSS

0.055

Percentile

93.3%

The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.

AI Score

9.9

Confidence

High

EPSS

0.055

Percentile

93.3%