WordPress security by component
Contact Form 7 Email Add on
Plugin description
Contact Form 7 Email Add on is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Nov 21, 2024; the highest published CVSS base score is 8.8.
Plugin slug:
cf7-email-add-onLatest vulnerability
CVE-2024-10898: Contact Form 7 Email Add on: Filesystem traversal
Contact Form 7 Email Add on is affected by filesystem traversal. Exploitation requires an authenticated contributor account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Nov 21, 2024 |
CVE-2024-10898
Contact Form 7 Email Add on: Filesystem traversal
Contact Form 7 Email Add on is affected by filesystem traversal. Exploitation requires an authenticated contributor account. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.8
NVD8.8
|