CVE-2021-24905
Advanced Contact form 7 DB <= 1.8.6 - Authenticated Arbitrary File Deletion
highIncorrect Authorization
8.8
CVSS Score
8.8
CVSS Score
high
Severity
1.8.7
Patched in
700d
Time to patch
Description
The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server. For example, removing the wp-config.php allows attackers to trigger WordPress setup again, gain administrator privileges and execute arbitrary code or display arbitrary content to the users.
CVSS Vector Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAttack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
High
Confidentiality
High
Integrity
High
Availability
Technical Details
Affected versions
<1.8.7PublishedFebruary 22, 2022
Last updatedJanuary 22, 2024
Affected pluginadvanced-cf7-db
Check if your site is affected.
Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.