Generate PDF using Contact Form 7 <= 4.0.6 - Cross-Site Request Forgery to Arbitrary File Deletion
CVE-2024-6317
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 9 July 2024
What is CVE-2024-6317?
The Generate PDF using Contact Form 7 plugin for WordPress contains a vulnerability that exposes systems to Cross-Site Request Forgery attacks, enabling unauthorized file uploads and deletions. This issue arises from the absence of nonce validation and insufficient validation of file paths during file operations within the 'wp_cf7_pdf_dashboard_html_page' function. As a result, unauthenticated attackers can exploit this flaw to remove critical files, such as wp-config.php, potentially leading to full site compromise and remote code execution if an administrator is tricked into executing a malicious link.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Generate PDF using Contact Form 7 * <= 4.0.6
References
EPSS Score
8% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published