Lucene search

K
wpvulndbWpvulndbWPVDB-ID:E6A76476-E086-473D-BC1E-3264C85B2441
HistoryMay 24, 2023 - 12:00 a.m.

Drag and Drop Multiple File Upload – Contact Form 7 < 1.3.6.6 - File Upload and File deletion via CSRF

2023-05-2400:00:00
wpscan.com
18
csrf
file upload
file deletion
validation
attackers
admin

EPSS

0.001

Percentile

27.6%

The plugin is lacking CSRF and validation when uploading or deleting files, which could allow attackers to make a logged-in admin upload or delete files via a CSRF attack.

EPSS

0.001

Percentile

27.6%

Related for WPVDB-ID:E6A76476-E086-473D-BC1E-3264C85B2441