CVE · High

CVE-2023-6449 — Contact Form 7 [contact-form-7] < 5.8.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6449 Contact Form 7 [contact-form-7] < 5.8.4 Unrestricted Upload of File with Dangerous Type High 7.2 < 5.8.4 5.8.4 2023-11-30

CVE-2023-6449

Contact Form 7 versions up to 5.8.3 contain a file upload vulnerability affecting authenticated users with editor privileges or higher, stemming from inadequate file type validation in the validate function and weak filename filtering in the wpcf7_antiscript_file_name function. Attackers can exploit this to upload arbitrary files to the server, though the htaccess rules typically prevent direct code execution and files are ordinarily removed immediately. In certain scenarios, particularly when other plugins extend file retention or when combined with local file inclusion flaws, this vulnerability could facilitate remote code execution.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.