CVE-2018-20979
Contact Form 7 versions before 5.0.4 contain a privilege escalation flaw that allows users with the Contributor role to modify contact forms, a capability restricted to Administrators and Editors by default. The vulnerability was addressed by explicitly defining the capability_type argument in the register_post_type() function call. Additionally, version 5.0.4 and later restrict the local file attachment feature to prevent absolute file paths referencing locations outside the wp-content directory, though relative paths and files within wp-content remain supported.
Based on public CVE data (MITRE/NVD).