Impact
The vulnerability in Contact Form Maker version 1.13.1 combines cross‑site request forgery with local file inclusion. Unsanitized "action" parameters in the admin‑ajax.php endpoint allow an unauthenticated attacker to craft a form that, when submitted, triggers directory traversal sequences to load arbitrary files. Access to the server’s file system can result in disclosure of sensitive information or the execution of malicious code.
Affected Systems
Web‑Dorado Contact Form Maker plugin for WordPress, version 1.13.1. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.1 denotes moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an attacker delivering a malicious form to a user, leveraging the CSRF-protected AJAX endpoint to include a chosen file. Because authentication is bypassed and the vector relies on user interaction, the exploitation likelihood is moderate but still significant.
OpenCVE Enrichment