Description
WordPress Plugin Custom Contact Forms is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to download and modify the database remotely or to upload files containing SQL statements which will be executed; this could lead to total compromise of the website. WordPress Plugin Custom Contact Forms version 5.1.0.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.1.0.4 or latest
References
Related Vulnerabilities
Omeka Server-Side Request Forgery (SSRF) Vulnerability (CVE-2023-3981)
WordPress Plugin NextGEN Gallery-WordPress Gallery 'swfupload.swf' Cross-Site Scripting (1.9.7)
WordPress Plugin WordPress Photo Gallery by Gallery Bank Cross-Site Scripting (3.0.228)