Description
WordPress Plugin Contact Form 7 Multi-Step Addon contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin Contact Form 7 Multi-Step Addon versions 1.0.4 - 1.0.5 are affected.
Remediation
Update to plugin version 1.0.7 or latest
References
Related Vulnerabilities
Drupal Improper Access Control Vulnerability (CVE-2016-5385)
WordPress Plugin Erident Custom Login and Dashboard Cross-Site Request Forgery (3.4.1)
Drupal Core 9.2.x Cross-Site Request Forgery (9.2.0 - 9.2.5)
WordPress Plugin Simple Sitemap-Create a Responsive HTML Sitemap Cross-Site Scripting (3.5.7)