The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
PoC: Check-WP-CVE-2020-35489
The (WordPress) website test script can be exploited for Unlimited File Upload via CVE-2020-35489
PoC: poc-CVE-2020-35489
Harnessing AI to hack the limits of possibility
PoC: poc-cve-2020-35489
poc-CVE-2020-35489
PoC: poc-CVE-2020-35489
poc-CVE-2020-35489
PoC: poc-CVE-2020-35489
POC for RCE with CVE-2020-35489
PoC: CVE-2020-35489
WordPress Contact Form 7 - Unrestricted File Upload
PoC: wp_CVE-2020-35489_checker
Verificador de Vulnerabilidade CVE-2020-35489 em Sites Wordpress
PoC: CVE-2020-35489
POC for Contact Form 7 < 5.3.2 - Unrestricted File Upload (Maybe Code execution )
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free