CVE-2019-25734

MEDIUM

Contact Form by WD 1.13.1 CSRF to Local File Inclusion

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25734. PoCs published by Peyman Forouzan.

AI-analyzed exploit summary This exploit demonstrates a CSRF to LFI vulnerability in Contact Form by WD plugin (version 1.13.1) by leveraging unsanitized AJAX actions to perform directory traversal and include local files. The PoC includes a form that submits a crafted request to exploit the vulnerability.

Description

Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by exploiting unsanitized action parameters. Attackers can craft malicious forms targeting the admin-ajax.php endpoint with directory traversal sequences in the GET action parameter to load files via CSRF, bypassing authentication on vulnerable AJAX actions.

Exploits (1)

exploitdb WORKING POC
by Peyman Forouzan · htmlwebappsphp
https://www.exploit-db.com/exploits/46661

This exploit demonstrates a CSRF to LFI vulnerability in Contact Form by WD plugin (version 1.13.1) by leveraging unsanitized AJAX actions to perform directory traversal and include local files. The PoC includes a form that submits a crafted request to exploit the vulnerability.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Contact Form by WD WordPress plugin 1.13.1
No auth needed
Prerequisites: WordPress installation with vulnerable plugin · Network access to the target
devstral-2 · analyzed Jun 04, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-46661
https://www.exploit-db.com/exploits/46661
Product product
Official Product Homepage
http://web-dorado.com/
Product product
Product Reference
https://wordpress.org/plugins/contact-form-maker
Third Party Advisory third-party-advisory
VulnCheck Advisory: Contact Form by WD 1.13.1 CSRF to Local File Inclusion
https://www.vulncheck.com/advisories/contact-form-by-wd-csrf-to-local-file-inclusion

Scores

CVSS v3 4.0
EPSS 0.0008
EPSS Percentile 24.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
Web-Dorado/Contact Form Maker 1.13.1
Published Jun 04, 2026
Tracked Since Jun 04, 2026