CVE-2020-35489
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may...
- Published
- Dec 17, 2020
- Updated
- Aug 4, 2024
- Assigning CNA
- mitre
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
Sources
3- CVE-2020-35489Scanner
WordPress Contact Form 7 - Unrestricted File Upload
- Check-WP-CVE-2020-35489Scanner
The (WordPress) website test script can be exploited for Unlimited File Upload via CVE-2020-35489
- Check-WP-CVE-2020-35489Scanner
Python script to detect WordPress sites vulnerable to CVE-2020-35489 in Contact Form 7, allowing unrestricted file uploads. Scans domains or lists and reports vulnerable versions.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.