PT-2022-9501 · WordPress · Advanced Contact Form 7 Db

Krzysztof Zając

·

Published

2022-03-21

·

Updated

2023-02-06

·

CVE-2021-24905

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advanced Contact form 7 DB WordPress plugin versions prior to 1.8.7
Description The issue allows any authenticated user to delete arbitrary files on the web server due to the lack of authorization and CSRF checks in the acf7 db edit scr file delete AJAX action, and failure to validate the file to be deleted. This can lead to significant consequences, such as removing the wp-config.php file, which enables attackers to trigger WordPress setup again. As a result, attackers can gain administrator privileges, execute arbitrary code, or display arbitrary content to users.
Recommendations For versions prior to 1.8.7, update to version 1.8.7 or later to resolve the issue. As a temporary workaround, consider disabling the acf7 db edit scr file delete AJAX action until a patch is available.

Exploit

Fix

Incorrect Authorization

CSRF

Weakness Enumeration

Related Identifiers

CVE-2021-24905

Affected Products

Advanced Contact Form 7 Db