Description
WordPress Plugin Custom Contact Forms is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to download and modify the database remotely or to upload files containing SQL statements which will be executed; this could lead to total compromise of the website. WordPress Plugin Custom Contact Forms version 5.1.0.3 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 5.1.0.4 or latest
References
Related Vulnerabilities
WordPress Plugin Newsletter Subscription Form Possible Remote Code Execution (1.1.2)
WordPress 4.3.x Cross-Domain Flash Injection Vulnerability (4.3 - 4.3.14)
WordPress 4.8.x Denial of Service Vulnerability (4.8 - 4.8.5)
WordPress Plugin Wordpress Uninstall Cross-Site Request Forgery (1.2.1)
WordPress Plugin Add Link to Facebook Cross-Site Scripting (2.3)