Wordpress Alert: Contact-form attachment disclosure
A form plugin stores uploaded attachments at guessable public URLs. Private submissions may be readable by anyone with the URL.
What it looks like
A form plugin stores uploaded attachments at guessable public URLs.
Why it matters
Private submissions may be readable by anyone with the URL.
What to check
Check attachment storage and download permissions.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP file upload guidance, WordPress roles and capabilities.
- Categories: WordPress
- Tags: #WordPress Security, #Plugin Security