Lucene search

K
osvGoogleOSV:CVE-2020-35489
HistoryDec 17, 2020 - 7:15 p.m.

CVE-2020-35489

2020-12-1719:15:14
Google
osv.dev
18
contact form 7
wordpress
unrestricted file upload
remote code execution
special characters

AI Score

7.8

Confidence

Low

EPSS

0.055

Percentile

93.3%

The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.

AI Score

7.8

Confidence

Low

EPSS

0.055

Percentile

93.3%