Description
Marc-Alexandre Montpas reported a security issue in the popular WordPress plugin Custom Contact Forms that would allow a user with no administrative privileges to download and modify your database remotely (no authentication required).
Remediation
Upgrade to the latest version of Custom Contact Forms (this problem was fixed in version 5.1.0.4).
References
Related Vulnerabilities
GlassFish Observable Discrepancy Vulnerability (CVE-2013-1620)
WordPress Plugin Product Addons & Fields for WooCommerce Arbitrary File Upload (1.1)
WordPress Plugin Spam protection, AntiSpam, FireWall by CleanTalk Cross-Site Scripting (5.136.3)
WordPress Plugin LiteSpeed Cache Cross-Site Scripting (3.6)
WordPress Plugin Advanced Forms for ACF Security Bypass (1.6.8)