A serious vulnerability in the Custom Contact Forms
-
I am using version 5.1.0.4 which claims to have fixed a vulnerability. I believe there are still security issues. My account was suspended by my host provider for sending spam emails. Upon investigation, it was evident that a hacker was exploiting Custom Contact Forms plugin. I updated the plugin to version 5.1.0.4 a week ago and the incidence happened on August 18, 2014. A serious vulnerability in the Custom Contact Forms
Below is the snippet from log file. Which confirms that there are still security issues with this plugin.
[18/Aug/2014:07:35:10 -0500] “POST /wp-content/plugins/custom-contact-forms/import/1408365293ccf.sql.php HTTP/1.1” 404 34536 “-” “Mozilla/5.0 (Windows NT 6.1; rv:12.0) Gecko/20130101 Firefox/10.0”
- The topic ‘A serious vulnerability in the Custom Contact Forms’ is closed to new replies.