Description
WordPress Plugin N-Media Website Contact Form with File Upload is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin N-Media Website Contact Form with File Upload version 1.5 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 1.6 or latest
References
Related Vulnerabilities
Magento Deserialization of Untrusted Data Vulnerability (CVE-2020-3716)
Open Resty Off-by-one Error Vulnerability (CVE-2021-23017)
WebLogic Improper Input Validation Vulnerability (CVE-2020-10693)
WordPress Plugin WP Social Sharing Cross-Site Scripting (2.2)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-0763)