WordPress Plugin Vulnerabilities

Spam Protect for Contact Form 7 < 1.2.10 - Editor+ Remote Code Execution

Description

The plugin allows logging to a PHP file, which could allow an attacker with editor access to achieve Remote Code Execution by using a crafted header

Proof of Concept

Affects Plugins

References

Classification

Type
RCE
OWASP top 10
CWE
CVSS

Miscellaneous

Original Researcher
Chiao-Lin Yu (Steven Meow)
Submitter
Chiao-Lin Yu (Steven Meow)
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-03-12 (about 21 days ago)
Added
2026-03-12 (about 20 days ago)
Last Updated
2026-03-12 (about 20 days ago)

Other