Impact
The Contact Form to Any API WordPress plugin prior to version 3.0.7 copies uploaded files into a publicly accessible directory using a predictable filename. This allows attackers to enumerate and download files that belong to other users without authentication. The flaw exposes sensitive user data and can be exploited via remote file discovery, classified under information exposure weaknesses.
Affected Systems
All installations of the Contact Form to Any API plugin with versions earlier than 3.0.7 are affected. The vulnerability is present for any site that uses the default file storage mechanism of the plugin and does not implement additional access controls on the upload directory.
Risk and Exploitability
The flaw can be leveraged by unauthenticated users with internet access to a vulnerable WordPress site. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, but the inherent lack of authentication and the exposure of user files make it a high‑risk issue that attackers can exploit once awareness of the plugin version is known.
OpenCVE Enrichment