WordPress插件Rocklobster Contact Form 7 < 5.3.2 任意文件上传漏洞

2020-12-18 Rocklobster Contact Form 7 PoC No

Description

The CVE-2020-35489 is discovered in the WordPress plugin Contact Form 7 5.3.1 and older versions. By exploiting this vulnerability, attackers could simply upload files of any type, bypassing all restrictions placed regarding the allowed upload-able file types on a website.

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References

Related Vulnerabilities