Arbitrary File Deletion Vulnerability in Contact Form Plugin
CVE-2024-7782
8.7HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 August 2024
What is CVE-2024-7782?
The Contact Form by Bit Form plugin for WordPress contains a vulnerability that allows authenticated users with Administrator-level access to delete arbitrary files from the server. This issue arises from inadequate file path validation in the iconRemove function, affecting versions 2.0 through 2.13.4. If exploited, this flaw could lead to the deletion of critical files (such as wp-config.php), potentially enabling remote code execution on the server.
Affected Version(s)
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 <= 2.13.4