Description
WordPress Plugin Custom Contact Forms is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to download and modify the database remotely or to upload files containing SQL statements which will be executed; this could lead to total compromise of the website. WordPress Plugin Custom Contact Forms version 5.1.0.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.1.0.4 or latest
References
Related Vulnerabilities
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2008-3325)
WordPress Plugin Unlimited PopUps SQL Injection (4.5.3)
Oracle Database Server CVE-2011-0882 Vulnerability (CVE-2011-0882)
WordPress Plugin Flickr Gallery PHP Object Injection (1.5.2)
WordPress Plugin BulletProof Security Information Disclosure (5.1)