← WordPress Vulnerabilities
WordPress security by component

Contact Form 7 Email Add on

Contact Form 7 Email Add on is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Nov 21, 2024; the highest published CVSS base score is 8.8.

Plugin slug: cf7-email-add-on

CVE-2024-10898: Contact Form 7 Email Add on: Filesystem traversal

Contact Form 7 Email Add on is affected by filesystem traversal. Exploitation requires an authenticated contributor account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedNov 21, 2024
Safe version guidanceSee mitigation notes
Published vulnerabilities for cf7-email-add-on
Safe version
Nov 21, 2024 CVE-2024-10898
Contact Form 7 Email Add on: Filesystem traversal
Contact Form 7 Email Add on is affected by filesystem traversal. Exploitation requires an authenticated contributor account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.8
NVD8.8