WordPress Plugin Vulnerabilities

Drag and Drop Multiple File Upload – Contact Form 7 < 1.3.5.5 - Unauthenticated Remote Code Execution

Description

The Drag and Drop Multiple File Upload – Contact Form 7 WordPress plugin was vulnerable to Remote Code Execution via file upload.

The plugin used a blacklist of dangerous file extensions that it did not allow to be uploaded, however, the extensions .phar and .phpt were not within the blacklist, which could be used to upload arbitrary PHP code.

Proof of Concept

Affects Plugins

References

Miscellaneous

Timeline

Publicly Published
2020-09-21 (about 5 years ago)
Added
2020-09-22 (about 5 years ago)
Last Updated
2020-09-23 (about 5 years ago)

Other