WORDFENCE-7bbead7c-47b9-473f-b335-6fae4b5998d6
high
📛 Threat Title
Contact Form Extender for Divi Builder <= 1.0.6 - Unauthenticated Arbitrary File Deletion via Path Traversal
Description
The Contact Form Extender for Divi Builder plugin for WordPress is vulnerable to Arbitrary File Deletion due to insufficient file path validation in the cfefd_remove_uploaded_file() function in all versions up to, and including, 1.0.6. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The nonce protecting this AJAX action is rendered into the public page source via wp_localize_script and is therefore retrievable by any unauthenticated visitor. Affected software — plugin: Contact Form Extender for Divi – Submissions DB & Extra Fields (affected: *-1.0.6). CVSS 7.5 (High) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (2)
Remediations (1)
-
Wordfence remediation: Contact Form Extender for Divi – Submissions DB & Extra FieldsWordfence
Update to version 1.0.7, or a newer patched version
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.