PT-2025-30373 · WordPress · Website Contact Form With File Upload

Published

2025-07-22

·

Updated

2025-12-16

·

CVE-2015-10137

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Website Contact Form With File Upload for WordPress versions up to 1.3.4
Description The Website Contact Form With File Upload plugin for WordPress is susceptible to arbitrary file uploads due to insufficient file type validation within the upload file() function. This allows unauthenticated attackers to upload arbitrary files to the affected site's server, potentially enabling remote code execution.
Recommendations Update Website Contact Form With File Upload for WordPress to a version later than 1.3.4.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2015-10137

Affected Products

Website Contact Form With File Upload