CVE-2024-9507

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 20

Summary

CVE-2024-9507 is a vulnerability affecting the Contact Form plugin by Bit Form for WordPress. This issue, occurring in all versions up to 2.15.2, allows authenticated attackers with Administrator-level access to execute a PHP filter chain attack. By exploiting the improper input validation in the iconUpload function, they can read the contents of arbitrary files on the server, potentially gaining access to sensitive information. This vulnerability poses a serious risk to WordPress sites using the affected plugin.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share