漏洞描述
WordPress Contact Form 7 before 1.3.3.3 allows unrestricted file upload and remote code execution by setting supported_type to php% and uploading a .php% file.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2020-12800↗github.comhttps://github.com/amartinsec/CVE-2020-12800↗packetstormsecurity.comhttps://packetstormsecurity.com/files/157951/WordPress-Drag-And-Drop-Multi-File-Uploader-Remote-Code-Execution.html↗wordpress.orghttps://wordpress.org/plugins/drag-and-drop-multiple-file-upload-contact-form-7/#developers↗