Vulnerabilities > Rocklobster > Contact Form 7 > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-12-17 CVE-2020-35489 Unrestricted Upload of File with Dangerous Type vulnerability in Rocklobster Contact Form 7
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
network
low complexity
rocklobster CWE-434
critical
10.0
2019-08-22 CVE-2018-20979 Unspecified vulnerability in Rocklobster Contact Form 7
The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.
network
low complexity
rocklobster
critical
9.8