CVE Database /
CVE-2024-3870
CVE · Medium
CVE-2024-3870 — Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-3870
|
Database Addon for Contact Form 7 – CFDB7 [contact-form-cfdb7] < 1.2.7 |
Exposure of Sensitive Information to an Unauthorized Actor |
Medium
5.3
|
< 1.2.7
|
1.2.7 |
2024-04-26 |
—
|
CVE-2024-3870
The Contact Form 7 Database Addon – CFDB7 plugin contains a sensitive information exposure flaw affecting versions 1.2.6.8 and earlier through the cfdb7_before_send_mail function. An attacker without authentication can exploit this vulnerability to access and retrieve sensitive user data, including personally identifiable information, from files that users have uploaded through the form.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings