Quick Contact Form WordPress Plugin Open Mail Relay Vulnerability
Vulnerability
A vulnerability allowing open mail relay has been identified in the Quick Contact Form plugin for WordPress, affecting all versions through 8.2.6. The issue arises from the 'qcf_validate_form' AJAX endpoint, which permits user-controlled parameters to dictate the 'from' email address. This flaw enables unauthenticated attackers to send emails to arbitrary recipients via the server, using details from the contact form submission.
Impact
Exploitation of this vulnerability allows for unauthorized email transmission to any recipient, using the server's resources.
Remediation
Users are advised to update the Quick Contact Form plugin to version 8.2.7 or a newer patched version.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
