WordPress Contact Form 7 - Full Path Disclosure
The WordPress Contact Form 7 plugin was detected to be vulnerable to Full Path Disclosure, where direct access to PHP files revealed the full server filesystem path and could aid further exploitation.
CVSS—