CVE-2018-20979

Contact Form 7
on wordpress-plugin

Published

Severity

CVSS v3:
9.8 CRITICAL
CVSS v2:
7.5 HIGH

Description

The contact-form-7 plugin before 5.0.4 for WordPress has privilege escalation because of capability_type mishandling in register_post_type.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:rocklobster:contact_form_7:*:*:*:*:*:wordpress:*:*n/a5.0.4*

External Links