Arbitrary File Deletion Vulnerability in Contact Form Plugin
CVE-2024-7782
8.7HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 August 2024
What is CVE-2024-7782?
The Contact Form by Bit Form plugin for WordPress contains a vulnerability that allows authenticated users with Administrator-level access to delete arbitrary files from the server. This issue arises from inadequate file path validation in the iconRemove function, affecting versions 2.0 through 2.13.4. If exploited, this flaw could lead to the deletion of critical files (such as wp-config.php), potentially enabling remote code execution on the server.
Affected Version(s)
Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 <= 2.13.4
References
EPSS Score
10% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
TANG Cheuk Hei