Description
WordPress Plugin Contact Form 7 is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin Contact Form 7 version 5.0.3 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 5.0.4 or latest
References
Related Vulnerabilities
WordPress Plugin WP Fountain Cross-Site Scripting (1.5.9)
phpMyFAQ Misinterpretation of Input Vulnerability (CVE-2023-0880)
phpMyAdmin Improper Authentication Vulnerability (CVE-2022-23807)
Coppermine Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2008-3481)
WordPress Plugin WordPress Meta Data and Taxonomies Filter (MDTF) PHP Object Injection (1.2.2)