PT-2026-28010 · WordPress+1 · Spam Protect For Contact Form 7+1

Publicado

2026-03-25

·

Atualizado

2026-04-08

·

CVE-2026-32496

CVSS v3.1

6.8

Média

VetorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NYSL Spam Protect for Contact Form 7 versions through 1.2.9
Description The software contains a flaw related to improper limitation of a pathname to a restricted directory, also known as Path Traversal. This allows an attacker to potentially access files and directories outside the intended scope. The issue impacts Spam Protect for Contact Form 7.
Recommendations Update to a version of NYSL Spam Protect for Contact Form 7 greater than 1.2.9.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32496

Produtos afetados

Contact Form 7
Spam Protect For Contact Form 7