Ultimate Addons for Contact Form 7
cpe:2.3:a:themefic:ultimate_addons_for_contact_form_7:*:*:*:*:wordpress:*:*
- <= 3.5.12
A vulnerability exists in the Ultimate Addons for Contact Form 7 WordPress plugin, in versions through 3.5.12, allowing authenticated users with Administrator-level access to upload arbitrary files. This issue arises from inadequate file type validation in the 'save_options' function, potentially leading to remote code execution.
Exploitation of this vulnerability could allow for arbitrary file uploads, with the possibility of executing uploaded files as code, depending on the file type and execution context.
To reproduce this vulnerability, log into the WordPress admin panel and navigate to 'Ultimate Addons -> Settings'. Intercept the 'save_options' POST request using a tool like Burp Suite. Append the file data, including a web shell named 'shell.php', into the request. After forwarding the modified request, the response will indicate a successful upload. The uploaded web shell can then be accessed and executed.
Users are advised to update the Ultimate Addons for Contact Form 7 plugin to version 3.5.13 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.