The WordPress Contact Form 7 plugin was detected to be vulnerable to Full Path Disclosure, where direct access to PHP files revealed the full server filesystem path and could aid further exploitation.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view