CVE-2020-35489

CRITICAL

Rocklobster Contact Form 7 < 5.3.2 - Unrestricted File Upload

Title source: rule

Description

The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.

Exploits (7)

nomisec SCANNER 31 stars
by dn9uy3n · poc
https://github.com/dn9uy3n/Check-WP-CVE-2020-35489
nomisec SCANNER 12 stars
by reneoliveirajr · poc
https://github.com/reneoliveirajr/wp_CVE-2020-35489_checker
github WORKING POC 4 stars
by incogbyte · pythonpoc
https://github.com/incogbyte/cves_exploits/tree/main/CVE-2020-35489
nomisec SCANNER 2 stars
by Cappricio-Securities · poc
https://github.com/Cappricio-Securities/CVE-2020-35489
nomisec SCANNER 2 stars
by X0UCYB3R · poc
https://github.com/X0UCYB3R/Check-WP-CVE-2020-35489

Scores

CVSS v3 10.0
EPSS 0.9033
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-434
Status published
Products (1)
rocklobster/contact_form_7 < 5.3.2
Published Dec 17, 2020
Tracked Since Feb 18, 2026