CVE · Medium

CVE-2026-32496 — Spam Protect for Contact Form 7 [wp-contact-form-7-spam-blocker] < 1.2.10

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-32496 Spam Protect for Contact Form 7 [wp-contact-form-7-spam-blocker] < 1.2.10 Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Media 6,8 < 1.2.10 1.2.10 2026-03-20

CVE-2026-32496

The Spam Protect for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 1.2.9. This makes it possible for authenticated attackers, with Editor-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Escanea tu sitio WordPress gratis

Sin registro, sin tarjeta de crédito — ingresa tu URL y obtén un informe de seguridad en segundos.