WordPress Contact Form 7 before 1.3.3.3 allows unrestricted file upload and remote code execution by setting supported_type to php% and uploading a .php% file.
id: CVE-2020-12800
info:
name: WordPress Contact Form 7 <1.3.3.3 - Remote Code Execution
author
...