CVE-2024-37555
WordPress Generate PDF using Contact Form 7 plugin <= 4.1.2 - CSRF to Arbitrary File Upload vulnerability
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Unrestricted Upload of File with Dangerous Type vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7.This issue affects Generate PDF using Contact Form 7: from n/a through <= 4.1.2.
| CWE | CWE-434 |
| Vendor | zealousweb |
| Product | generate pdf using contact form 7 |
| Published | Jul 9, 2024 |
| Last Updated | Apr 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for zealousweb generate pdf using contact form 7
Be the first to know when new unknown vulnerabilities affecting zealousweb generate pdf using contact form 7 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
ZealousWeb / Generate PDF using Contact Form 7
0 โค 4.1.2
References
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/generate-pdf-using-contact-form-7/vulnerability/wordpress-generate-pdf-using-contact-form-7-plugin-4-0-6-arbitrary-file-upload-vulnerability?_s_id=cve patchstack.com: https://patchstack.com/database/vulnerability/generate-pdf-using-contact-form-7/wordpress-generate-pdf-using-contact-form-7-plugin-4-0-6-arbitrary-file-upload-vulnerability?_s_id=cve
Credits
Peng Zhou | Patchstack Bug Bounty Program