PT-2026-28010 · WordPress+1 · Spam Protect For Contact Form 7+1
Publicado
2026-03-25
·
Atualizado
2026-04-08
·
CVE-2026-32496
CVSS v3.1
6.8
Média
| Vetor | AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NYSL Spam Protect for Contact Form 7 versions through 1.2.9
Description
The software contains a flaw related to improper limitation of a pathname to a restricted directory, also known as Path Traversal. This allows an attacker to potentially access files and directories outside the intended scope. The issue impacts Spam Protect for Contact Form 7.
Recommendations
Update to a version of NYSL Spam Protect for Contact Form 7 greater than 1.2.9.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Contact Form 7
Spam Protect For Contact Form 7