### [CVE-2020-35489](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35489) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters. ### POC #### Reference - https://wpscan.com/vulnerability/10508 - https://www.jinsonvarghese.com/unrestricted-file-upload-in-contact-form-7/ #### Github - https://github.com/0xget/cve-2001-1473 - https://github.com/ARPSyndicate/cvemon - https://github.com/ARPSyndicate/kenzer-templates - https://github.com/Cappricio-Securities/CVE-2020-35489 - https://github.com/El-Palomo/MR-ROBOT-1 - https://github.com/Elsfa7-110/kenzer-templates - https://github.com/SexyBeast233/SecBooks - https://github.com/StarCrossPortal/scalpel - https://github.com/X0UCYB3R/Check-WP-CVE-2020-35489 - https://github.com/anonymous364872/Rapier_Tool - https://github.com/apif-review/APIF_tool_2024 - https://github.com/d4n-sec/d4n-sec.github.io - https://github.com/developer3000S/PoC-in-GitHub - https://github.com/dn9uy3n/Check-WP-CVE-2020-35489 - https://github.com/hectorgie/PoC-in-GitHub - https://github.com/jinsonvarghese/jinsonvarghese - https://github.com/nomi-sec/PoC-in-GitHub - https://github.com/reneoliveirajr/wp_CVE-2020-35489_checker - https://github.com/youcans896768/APIV_Tool