Wordpress Alert: Contact-form attachment disclosure

A form plugin stores uploaded attachments at guessable public URLs. Private submissions may be readable by anyone with the URL.

What it looks like

A form plugin stores uploaded attachments at guessable public URLs.

Why it matters

Private submissions may be readable by anyone with the URL.

What to check

Check attachment storage and download permissions.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP file upload guidance, WordPress roles and capabilities.