WordPress Plugin Vulnerabilities
Spam Protect for Contact Form 7 < 1.2.10 - Editor+ Remote Code Execution
Description
The plugin allows logging to a PHP file, which could allow an attacker with editor access to achieve Remote Code Execution by using a crafted header
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
RCE
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Chiao-Lin Yu (Steven Meow)
Submitter
Chiao-Lin Yu (Steven Meow)
Submitter website
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-03-12 (about 21 days ago)
Added
2026-03-12 (about 20 days ago)
Last Updated
2026-03-12 (about 20 days ago)