CyberRota Analysis
AI-GeneratedThe Contact Form to Any API WordPress plugin versions prior to 3.0.7 are vulnerable due to improper file handling, which allows unauthenticated attackers to access and download user-submitted files from a publicly accessible directory. This exposure can lead to data leakage and privacy violations. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.
Original NVD Description
The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users.