CVE-2023-6449
Contact Form 7 versions up to 5.8.3 contain a file upload vulnerability affecting authenticated users with editor privileges or higher, stemming from inadequate file type validation in the validate function and weak filename filtering in the wpcf7_antiscript_file_name function. Attackers can exploit this to upload arbitrary files to the server, though the htaccess rules typically prevent direct code execution and files are ordinarily removed immediately. In certain scenarios, particularly when other plugins extend file retention or when combined with local file inclusion flaws, this vulnerability could facilitate remote code execution.
Based on public CVE data (MITRE/NVD).