Vulnerabilities > Rocklobster > Contact Form 7 > 3.6

DATE CVE VULNERABILITY TITLE RISK
2024-01-11 CVE-2023-6630 Authorization Bypass Through User-Controlled Key vulnerability in Rocklobster Contact Form 7
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.0 via the CF7_get_custom_field and CF7_get_current_user shortcodes due to missing validation on a user controlled key.
network
low complexity
rocklobster CWE-639
4.3
2023-12-01 CVE-2023-6449 Unrestricted Upload of File with Dangerous Type vulnerability in Rocklobster Contact Form 7
The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'validate' function and insufficient blocklisting on the 'wpcf7_antiscript_file_name' function in versions up to, and including, 5.8.3.
network
low complexity
rocklobster CWE-434
7.2
2020-12-17 CVE-2020-35489 Unrestricted Upload of File with Dangerous Type vulnerability in Rocklobster Contact Form 7
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
network
low complexity
rocklobster CWE-434
critical
10.0
2019-08-22 CVE-2018-20979 Unspecified vulnerability in Rocklobster Contact Form 7
The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.
network
low complexity
rocklobster
7.5
2014-03-14 CVE-2014-2265 Permissions, Privileges, and Access Controls vulnerability in Rocklobster Contact Form 7 3.6/3.7/3.7.1
Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 parameter.
network
low complexity
rocklobster CWE-264
5.0