PT-2026-28010 · WordPress+1 · Spam Protect For Contact Form 7+1
Published
2026-03-25
·
Updated
2026-04-08
·
CVE-2026-32496
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NYSL Spam Protect for Contact Form 7 versions through 1.2.9
Description
The software contains a flaw related to improper limitation of a pathname to a restricted directory, also known as Path Traversal. This allows an attacker to potentially access files and directories outside the intended scope. The issue impacts Spam Protect for Contact Form 7.
Recommendations
Update to a version of NYSL Spam Protect for Contact Form 7 greater than 1.2.9.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contact Form 7
Spam Protect For Contact Form 7