Skip to main content

Security Update Released for Contact Form 7 WordPress Plugin

Report a cyber attack: call 0300 303 5222 or email [email protected]

Affected platforms

The following platforms are known to be affected:

Contact Form 7 plugin for WordPress Versions: 5.3.1 and earlier


Threat details

Introduction

Contact Form 7 has released a security update to address an unrestricted file upload and remote code execution vulnerability. A remote unauthenticated attacker could exploit this vulnerability to take control of an affected system.


Remediation advice

Affected organisations are encouraged to review the Contact Form 7 release page and apply the relevant update.


Last edited: 21 December 2021 10:48 am