Description
WordPress Plugin Save Contact Form 7 is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Save Contact Form 7 version 2.0 is vulnerable; prior versions may also be affected.
Remediation
Edit the source code to ensure that only users with the "manage_options" capability can view submissions or disable the plugin until a fix is available
References
Related Vulnerabilities
WordPress Plugin WP Super Cache Cross-Site Scripting (1.7.2)
OpenSSL Use of a Broken or Risky Cryptographic Algorithm Vulnerability (CVE-2018-0735)
WordPress Plugin Bold Page Builder Security Bypass (2.3.1)
Moodle Other Vulnerability (CVE-2006-4942)
PHP Inadequate Encryption Strength Vulnerability (CVE-2020-7069)