PT-2026-28010 · WordPress+1 · Spam Protect For Contact Form 7+1

Published

2026-03-25

·

Updated

2026-04-08

·

CVE-2026-32496

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NYSL Spam Protect for Contact Form 7 versions through 1.2.9
Description The software contains a flaw related to improper limitation of a pathname to a restricted directory, also known as Path Traversal. This allows an attacker to potentially access files and directories outside the intended scope. The issue impacts Spam Protect for Contact Form 7.
Recommendations Update to a version of NYSL Spam Protect for Contact Form 7 greater than 1.2.9.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32496

Affected Products

Contact Form 7
Spam Protect For Contact Form 7