
Cloud Vulnerability DB
A community-led vulnerabilities database
The Advanced Contact form 7 DB WordPress plugin before version 1.8.7 contained a critical security vulnerability identified as CVE-2021-24905. This vulnerability was related to missing authorization and CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, combined with inadequate file validation for deletion operations (WPScan).
The vulnerability has a CVSS v3.1 Base Score of 8.0 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H. The issue stems from two main weaknesses: Cross-Site Request Forgery (CSRF) (CWE-352) and Incorrect Authorization (CWE-863). The vulnerability affects all versions of the plugin up to (but not including) version 1.8.7, with version 1.8.3 adding some capability and CSRF checks, though path traversal was not fully fixed until 1.8.7 (NVD).
The vulnerability allows any authenticated user to delete arbitrary files on the web server. A particularly severe exploitation scenario involves deleting the wp-config.php file, which would enable attackers to trigger WordPress setup again, potentially gaining administrator privileges and subsequently executing arbitrary code or displaying arbitrary content to users (WPScan).
The recommended mitigation is to update the Advanced Contact form 7 DB plugin to version 1.8.7 or later, which fully addresses the vulnerability including the path traversal issue. While version 1.8.3 added some security improvements with capability and CSRF checks, it did not completely resolve all security concerns (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."