+ Reply to Thread
Page 1 of 2 1 2 LastLast
Results 1 to 10 of 12

Thread: Contact Form 7 Security Vulnerability

  1. #1
    Jeffro's Avatar
    Jeffro is offline WPTavern Forum Admin
    Join Date
    Jan 2009
    Location
    Ohio
    Posts
    2,107

    Default Contact Form 7 Security Vulnerability

    Mark Jaquith over Twitter today mentioned that Contact Form 7 was being exploited and that anyone using it should uninstall it. That's what I've done to both WPTavern and Jeffro2pt0 but I have yet to see any detailed information regarding the hack or exploit. Anyone else?

  2. #2
    Len's Avatar
    Len
    Len is offline Big Tipper
    Join Date
    Jan 2009
    Location
    Winnipeg, MB Canada
    Posts
    369

    Default

    I use Dagon Design Form Mailer myself. I just put the word out on the WP forums.

  3. #3
    Ryan's Avatar
    Ryan is offline WPTavern Forum Moderator
    Join Date
    Jan 2009
    Location
    New Zealand
    Posts
    2,418

    Default

    Darn. I use this on two sites :(

    Hopefully they get it fixed ASAP.

  4. #4
    Ryan's Avatar
    Ryan is offline WPTavern Forum Moderator
    Join Date
    Jan 2009
    Location
    New Zealand
    Posts
    2,418

  5. #5
    Jeffro's Avatar
    Jeffro is offline WPTavern Forum Admin
    Join Date
    Jan 2009
    Location
    Ohio
    Posts
    2,107

    Default

    Yep been in touch with that thread. I have a post going live at 7AM to let people know of the *potential* security problem with the plugin. Hope it is quickly fixed as it's my favorite contact form plugin. Works perfectly for me and no spam.

  6. #6
    PaulCunningham's Avatar
    PaulCunningham is offline Hello World
    Join Date
    Jan 2009
    Location
    Brisbane, Australia
    Posts
    61

    Default

    Just disabled it across my sites. Kind of painful to do, but security trumps convenience.

    Hope the problem is solved in a couple days so I don't have to go rolling out an entirely new plugin everywhere...

  7. #7
    bradgillap's Avatar
    bradgillap is offline Hello World
    Join Date
    Apr 2009
    Location
    Welland, Ontario, Canada
    Posts
    28

    Default

    Looks like the security issues may have been resolved. I didn't see any details but the developer made a post today.

    http://ideasilo.wordpress.com/2009/0...t-form-7-1951/
    April 23, 2009
    I have recently released Contact Form 7 1.9.5.1. This update includes several security fixes, so upgrading quickly is highly recommended.

  8. #8
    Jeffro's Avatar
    Jeffro is offline WPTavern Forum Admin
    Join Date
    Jan 2009
    Location
    Ohio
    Posts
    2,107

    Default

    Thanks for the update. Going to have to reinstall it and reconfigure it on my sites again. Looks like the security vulnerability had something to do with not having default restrictions on file types and file size uploads.

    I think I need to donate $20.00 to this guy for fixing it as I love this plugin.

  9. #9
    bradgillap's Avatar
    bradgillap is offline Hello World
    Join Date
    Apr 2009
    Location
    Welland, Ontario, Canada
    Posts
    28

    Default

    It's a fantastic plugin. The forms setup in the config page is a little ugly but you can't knock a plugin that addresses security issues like this so quickly.

  10. #10
    Jeffro's Avatar
    Jeffro is offline WPTavern Forum Admin
    Join Date
    Jan 2009
    Location
    Ohio
    Posts
    2,107

    Default

    Yeah, ended up giving the guy $20.00 for fixing it so quickly. He was really appreciative of the donation. I thought it sucked that such an awesome plugin only made him about $100.00 in total so far.

+ Reply to Thread
Page 1 of 2 1 2 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts