← WordPress Vulnerabilities
WordPress security by component

CF7 Reply Manager

CF7 Reply Manager is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Nov 16, 2024; the highest published CVSS base score is 9.9.

Plugin slug: cf7-reply-manager

CVE-2024-52404: CF7 Reply Manager: Dangerous file upload

CF7 Reply Manager is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedNov 16, 2024
Safe version guidanceSee mitigation notes
Published vulnerabilities for cf7-reply-manager
Safe version
Nov 16, 2024 CVE-2024-52404
CF7 Reply Manager: Dangerous file upload
CF7 Reply Manager is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE9.9
NVDPending