Contact Form 7 Campaign Monitor Extension [contact-form-7-campaign-monitor-extension] <= 0.4.67 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in Renzo Johnson Contact Form 7 Campaign Monitor Extension allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Contact Form 7 Campaign Monitor Extension: from n/a through 0.4.67.
- Affected:
- up to 0.4.67
- Fix:
- No patched version reported
- Disclosed:
- Nov 1, 2024
CVE-2024-44019 on NVD →
Contact Form 7 Campaign Monitor Extension <= 0.4.67 - Missing Authorization to Unauthenticated Arbitrary File Deletion
critical
The Contact Form 7 Campaign Monitor Extension plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 0.4.67. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily...
- CVSS:
- 9.8
- Affected:
- up to 0.4.67
- Fix:
- No patched version reported
- Disclosed:
- Sep 24, 2024
CVE-2024-44019 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database