The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the iconRemove function in versions 2.0 to 2.13.4. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Metrics
Affected Vendors & Products
References
History
Tue, 03 Sep 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 26 Aug 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Bitapps
Bitapps contact Form Builder |
|
CPEs | cpe:2.3:a:bitapps:contact_form_builder:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Bitapps
Bitapps contact Form Builder |
Tue, 20 Aug 2024 03:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the iconRemove function in versions 2.0 to 2.13.4. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). | |
Title | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder 2.0 - 2.13.4 - Authenticater (Administrator+) Arbitrary File Deletion | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-08-20T03:21:11.466Z
Updated: 2024-09-03T15:14:10.502Z
Reserved: 2024-08-13T23:15:01.483Z
Link: CVE-2024-7782
Vulnrichment
Updated: 2024-09-03T15:14:03.508Z
NVD
Status : Analyzed
Published: 2024-08-20T04:15:11.203
Modified: 2024-08-26T18:21:12.203
Link: CVE-2024-7782
Redhat
No data.