Arbitrary File Deletion Vulnerability in Contact Form Plugin
CVE-2024-7782

8.7HIGH

What is CVE-2024-7782?

The Contact Form by Bit Form plugin for WordPress contains a vulnerability that allows authenticated users with Administrator-level access to delete arbitrary files from the server. This issue arises from inadequate file path validation in the iconRemove function, affecting versions 2.0 through 2.13.4. If exploited, this flaw could lead to the deletion of critical files (such as wp-config.php), potentially enabling remote code execution on the server.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 <= 2.13.4

References

EPSS Score

10% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TANG Cheuk Hei
.