VendorsWeb-Doradocontact_formall versions
Vulnerabilities

Web-Dorado WebDorado Contact Form 1.13.5 for WordPress

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2019-11591
The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.
Published 2019-04-29 · Modified
8.8EPSS 0.011