The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an attacker with editor access to achieve Remote Code Execution by using a crafted header
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 02 Apr 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an attacker with editor access to achieve Remote Code Execution by using a crafted header | |
| Title | Spam Protect for Contact Form 7 < 1.2.10 - Editor+ Remote Code Execution | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-04-02T06:00:10.124Z
Reserved: 2026-01-28T14:37:11.670Z
Link: CVE-2026-1540
No data.
Status : Received
Published: 2026-04-02T06:16:22.337
Modified: 2026-04-02T06:16:22.337
Link: CVE-2026-1540
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.