PT-2022-9501 · WordPress · Advanced Contact Form 7 Db
Krzysztof Zając
·
Published
2022-03-21
·
Updated
2023-02-06
·
CVE-2021-24905
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Advanced Contact form 7 DB WordPress plugin versions prior to 1.8.7
Description
The issue allows any authenticated user to delete arbitrary files on the web server due to the lack of authorization and CSRF checks in the
acf7 db edit scr file delete AJAX action, and failure to validate the file to be deleted. This can lead to significant consequences, such as removing the wp-config.php file, which enables attackers to trigger WordPress setup again. As a result, attackers can gain administrator privileges, execute arbitrary code, or display arbitrary content to users.Recommendations
For versions prior to 1.8.7, update to version 1.8.7 or later to resolve the issue.
As a temporary workaround, consider disabling the
acf7 db edit scr file delete AJAX action until a patch is available.Exploit
Fix
Incorrect Authorization
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Advanced Contact Form 7 Db