CVE-2020-35489: Rocklobster Contact Form 7

Critical severity, CVSS 10.0. EPSS: 89.3% chance of exploitation in the next 30 days.

The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.

Affected products

  • Rocklobster Contact Form 7: before 5.3.2 (fixed in 5.3.2)

Published 2020-12-17. Last modified 2026-06-17.