.. / CVE-2020-12800

Exploit for WordPress Contact Form 7 <1.3.3.3 - Remote Code Execution (CVE-2020-12800)

Description:

WordPress Contact Form 7 before 1.3.3.3 allows unrestricted file upload and remote code execution by setting supported_type to php% and uploading a .php% file.

Nuclei Template

View the template here CVE-2020-12800.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-12800.yaml
Copy

References:

https://github.com/amartinsec/CVE-2020-12800
https://wordpress.org/plugins/drag-and-drop-multiple-file-upload-contact-form-7/#developers
https://nvd.nist.gov/vuln/detail/CVE-2020-12800
https://packetstormsecurity.com/files/157951/WordPress-Drag-And-Drop-Multi-File-Uploader-Remote-Code-Execution.html