PT-2020-6885 · WordPress · Contact Form 7

Jinson Varghese Behanan

·

Published

2020-12-17

·

Updated

2026-03-10

·

CVE-2020-35489

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Contact Form 7 versions prior to 5.3.2
Description The issue is related to an Unrestricted File Upload vulnerability in the Contact Form 7 plugin for WordPress, which can lead to remote code execution. This is because a filename may contain special characters. The vulnerability affects over 5 million active installations. It allows an attacker to upload files of arbitrary type and execute arbitrary code.
Recommendations For versions prior to 5.3.2, update to version 5.3.2 or later to resolve the issue. As a temporary workaround, consider restricting file uploads to prevent exploitation until the update is applied. Avoid using filenames that contain special characters in the affected plugin until the issue is resolved.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2023-03193
CVE-2020-35489

Affected Products

Contact Form 7