漏洞描述
WordPress Contact Form plugin files are publicly accessible without ABSPATH protection, exposing sensitive server path information through PHP error messages when accessed directly.
影响产品
wp-plugincontact-form-7查看产品 →wp-plugincontact-form-7-signature-addon查看产品 →wp-plugincontact-form-7-style查看产品 →wp-plugincontact-form-add查看产品 →wp-plugincontact-form-manager查看产品 →wp-plugincontact-form-plugin查看产品 →wp-plugincustom-css-js查看产品 →wp-pluginquick-contact-form查看产品 →wp-pluginsimple-contact-form查看产品 →wp-pluginvery-simple-contact-form查看产品 →supsysticcontact_form查看产品 →bestwebsoftcontact_form_multi查看产品 →creative-solutionscreative_contact_form查看产品 →未知厂商contact-form-generator查看产品 →
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。