WordPress 123ContactForm plugin <= 1.5.6 - Arbitrary Post Creation vulnerability
Arbitrary Post Creation vulnerability found by Sucuri in WordPress 123ContactForm plugin (versions <= 1.5.6).
2021-01-20 - we were unable to find a patched version of this plugin.
Notification from WordPress plugin repository: "This plugin has been closed as of October 27, 2020 and is not available for download. Reason: Security Issue."
Type Unknown OWASP Top 10 A7: Missing Function Level Access Control