Description
WordPress Plugin Custom Contact Forms is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to download and modify the database remotely or to upload files containing SQL statements which will be executed; this could lead to total compromise of the website. WordPress Plugin Custom Contact Forms version 5.1.0.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.1.0.4 or latest
References
Related Vulnerabilities
WordPress Plugin xili-tidy-tags Cross-Site Request Forgery (1.12.03)
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.1)
Oracle Database Server Other Vulnerability (CVE-2006-1869)
Jboss EAP Improper Input Validation Vulnerability (CVE-2010-1871)
WordPress Plugin Category Grid View Gallery Cross-Site Scripting (2.3.3)