Description
WordPress Plugin Zedna Contact form is prone to a directory traversal vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Zedna Contact form version 1.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2 or latest
References
Related Vulnerabilities
WordPress Plugin BuddyPress Customer.io Analytics Integration Cross-Site Request Forgery (1.1.6)
Oracle Database Server CVE-2011-0880 Vulnerability (CVE-2011-0880)
Ruby Improper Input Validation Vulnerability (CVE-2008-3657)
MyBB Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-4624)