Advanced Contact form 7 DB <= 1.8.6 - Authenticated Arbitrary File Deletion

2022-02-22 00:00
Krzysztof Zając

Strategic Overview

Status
Patched in 1.8.7
Affected Version< 1.8.7
CVSS8.8High
CVECVE-2021-24905
View all Advanced Contact form 7 DB vulnerabilities

Vulnerability Overview

The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server. For example, removing the wp-config.php allows attackers to trigger WordPress setup again, gain administrator privileges and execute arbitrary code or display arbitrary content to the users.

Technical Analysis

REMEDIATION: Update to version 1.8.7, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C