Arbitrary File Deletion Vulnerability in Contact Form Plugin
CVE-2024-7782
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 August 2024
What is CVE-2024-7782?
The Contact Form by Bit Form plugin for WordPress contains a vulnerability that allows authenticated users with Administrator-level access to delete arbitrary files from the server. This issue arises from inadequate file path validation in the iconRemove function, affecting versions 2.0 through 2.13.4. If exploited, this flaw could lead to the deletion of critical files (such as wp-config.php), potentially enabling remote code execution on the server.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 <= 2.13.4
References
EPSS Score
10% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved