Description
WordPress Plugin N-Media Website Contact Form with File Upload is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin N-Media Website Contact Form with File Upload version 1.5 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 1.6 or latest
References
Related Vulnerabilities
WordPress Plugin Banner Effect Header Cross-Site Scripting (1.2.7)
WordPress Plugin PowerPress Podcasting by Blubrry Cross-Site Scripting (10.0)
WordPress Plugin Easy Digital Downloads Attach Accounts to Orders Cross-Site Scripting (2.0.1)
PHP unspecified remote arbitrary file upload vulnerability
WordPress Plugin Login Security Solution Multiple Unspecified Vulnerabilities (0.50.0)