CVE · Critical

CVE-2018-20979 — Contact Form 7 [contact-form-7] < 5.0.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-20979 Contact Form 7 [contact-form-7] < 5.0.4 Critical 9.8 < 5.0.4 5.0.4 2018-09-04

CVE-2018-20979

Contact Form 7 versions before 5.0.4 contain a privilege escalation flaw that allows users with the Contributor role to modify contact forms, a capability restricted to Administrators and Editors by default. The vulnerability was addressed by explicitly defining the capability_type argument in the register_post_type() function call. Additionally, version 5.0.4 and later restrict the local file attachment feature to prevent absolute file paths referencing locations outside the wp-content directory, though relative paths and files within wp-content remain supported.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.