Description
Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by exploiting unsanitized action parameters. Attackers can craft malicious forms targeting the admin-ajax.php endpoint with directory traversal sequences in the GET action parameter to load files via CSRF, bypassing authentication on vulnerable AJAX actions.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Credits
Panagiotis Vagenas
References
www.exploit-db.com/exploits/46661 (ExploitDB-46661)
web-dorado.com/ (Official Product Homepage)
wordpress.org/plugins/contact-form-maker (Product Reference)
www.vulncheck.com/...form-by-wd-csrf-to-local-file-inclusion (VulnCheck Advisory: Contact Form by WD 1.13.1 CSRF to Local File Inclusion)