Description
WordPress Plugin Custom Contact Forms is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to download and modify the database remotely or to upload files containing SQL statements which will be executed; this could lead to total compromise of the website. WordPress Plugin Custom Contact Forms version 5.1.0.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.1.0.4 or latest
References
Related Vulnerabilities
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-7572)
MySQL CVE-2014-6559 Vulnerability (CVE-2014-6559)
Sqlite CVE-2023-36191 Vulnerability (CVE-2023-36191)
WordPress Plugin BP Portfolio Cross-Site Scripting (1.0.2)
Django Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-46695)