疑似Oday
The WordPress Contact Form 7 plugin was detected to be vulnerable to Full Path Disclosure, where direct access to PHP files revealed the full server filesystem path and could aid further exploitation.
id: wp-contact-form-7-fpd
info:
name: WordPress Contact Form 7 - Full Path Disclosure
author: p
...