CVE Published: 28/02/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: WPScan |
Vendor: Unknown |
Product: Contact Forms – Drag & Drop Contact Form Builder Status : PUBLISHED
CVE-2021-24689 Description
The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin through 1.0.5 allows high privilege users to download arbitrary files from the web server via a path traversal attack