CVE-2019-25734

Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by exploiting unsanitized action parameters. Attackers can craft malicious forms targeting the admin-ajax.php endpoint with directory traversal sequences in the GET action parameter to load files via CSRF, bypassing authentication on vulnerable AJAX actions.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-04 14:16

Updated : 2026-07-22 20:10


NVD link : CVE-2019-25734

Mitre link : CVE-2019-25734

CVE.ORG link : CVE-2019-25734


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')