Description
WordPress Plugin Contact Form 7 Multi-Step Addon contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin Contact Form 7 Multi-Step Addon versions 1.0.4 - 1.0.5 are affected.
Remediation
Update to plugin version 1.0.7 or latest
References
Related Vulnerabilities
WordPress Plugin Contextual Related Posts Cross-Site Request Forgery (1.8.6)
WordPress Plugin Helpie FAQ-WordPress FAQ Accordion Security Bypass (0.7)
WordPress Plugin Integration for Contact Form 7 and Zoho Cross-Site Scripting (1.1.7)
Oracle Database Server CVE-2010-0851 Vulnerability (CVE-2010-0851)