WordPress 插件 “Ultra Addons for Contact Form 7” 在 3.5.50 及更早的所有版本中存在任意文件上传漏洞,原因是函数 中的文件类型验证不充分。未经身份验证的攻击者可借此在受影响站点的服务器上上传任意文件,从而可能导致远程代码执行。请注意:该漏洞仅在插件的 PDF 生成器模块被启用时才可被利用,而该模块默认处于禁用状态。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| themefic | Ultra Addons for Contact Form 7 | 0 ~ 3.5.50 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet