What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions.
Explanation of Vulnerability in Simple Terms
This WordPress plugin for Contact Form 7 is vulnerable to cross-site request forgery (CSRF). An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions like uploading files or modifying form settings without the admin's knowledge or consent. The vulnerability affects versions up to 1.3.6.5.
What an attacker can do
Trick a logged-in admin into uploading files or changing form settings without their knowledge.
Potential impact on your site
Attackers can modify your Contact Form 7 configuration or upload unwanted files if an admin visits a compromised site.
Conditions required to exploit
Admin must visit a malicious webpage while logged into WordPress.
Key dates
External resources
Related vulnerabilities