Description
WordPress Plugin Contact Form 7 Multi-Step Addon contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin Contact Form 7 Multi-Step Addon versions 1.0.4 - 1.0.5 are affected.
Remediation
Update to plugin version 1.0.7 or latest
References
Related Vulnerabilities
Drupal CVE-2022-25278 Vulnerability (CVE-2022-25278)
Trac Incorrect Default Permissions Vulnerability (CVE-2010-5108)
Mailman Other Vulnerability (CVE-2003-0992)
WordPress Plugin XCloner-Backup and Restore Multiple Vulnerabilities (3.1.2)
WordPress Plugin Tutor LMS-eLearning and online course solution Cross-Site Scripting (2.0.9)