WordPress Plugin Vulnerabilities
Drag and Drop Multiple File Upload – Contact Form 7 < 1.3.5.5 - Unauthenticated Remote Code Execution
Description
The Drag and Drop Multiple File Upload – Contact Form 7 WordPress plugin was vulnerable to Remote Code Execution via file upload.
The plugin used a blacklist of dangerous file extensions that it did not allow to be uploaded, however, the extensions .phar and .phpt were not within the blacklist, which could be used to upload arbitrary PHP code.
Proof of Concept
Affects Plugins
References
Miscellaneous
Verified
No
WPVDB ID
Timeline
Publicly Published
2020-09-21 (about 5 years ago)
Added
2020-09-22 (about 5 years ago)
Last Updated
2020-09-23 (about 5 years ago)