CVE-2024-10898 | krishaweb Contact Form 7 Email Add On Plugin up to 1.9 on WordPress cf7_email_add_on_add_admin_template filename control
A vulnerability was found in krishaweb Contact Form 7 Email Add On Plugin up to 1.9 on WordPress and classified as critical. Affected by this issue is the function cf7_email_add_on_add_admin_template. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is handled as CVE-2024-10898. The attack may be launched remotely. There is no exploit available.