Understanding the Critical Threat of CVE-2015-10137
A serious security flaw has been found in the “Website Contact Form With File Upload” plugin for WordPress. This vulnerability allows attackers to upload harmful files onto your website server without needing to log in. This kind of attack can lead to someone taking complete control of your website, which is a major security risk.
The problem lies in how the plugin handles file uploads. It doesn’t properly check the type of files being uploaded, making it easy for malicious files to bypass security checks. If exploited, an attacker could potentially execute harmful code on your server, leading to a full compromise of your WordPress site.
CVE Details
Product: Website Contact Form With File Upload plugin for WordPress
Published: July 22, 2025
Severity: Critical
Status: Analyzed
Affected Products
This critical vulnerability impacts the “Website Contact Form With File Upload” plugin for WordPress, specifically in versions up to, and including, 1.3.4. If you are using any version of this plugin equal to or older than 1.3.4, your website is at risk.
Current Status
The vulnerability, identified as CVE-2015-10137, has been “Analyzed.” This means cybersecurity experts have thoroughly investigated and confirmed the existence and nature of the flaw. While its details are well-understood, it underscores the importance for users to take immediate action to protect their sites.
Severity Level
With a CVSS score of 9.8 out of 10, this vulnerability is rated as Critical. This high severity indicates that the flaw is easy to exploit and can have devastating consequences. Attackers can leverage this vulnerability to gain remote code execution, which means they can run their own commands on your server, potentially stealing data, defacing your website, or using it to launch further attacks. Given the unauthenticated nature of the exploit, any website running an affected version is a prime target.
Possible Solutions
If you are using the Website Contact Form With File Upload plugin, it is crucial to take action immediately. The primary solution is to update your plugin to a version beyond 1.3.4, which should contain the necessary fixes for the file type validation issue. Always ensure your WordPress plugins are kept up-to-date.
If an update is not available, or if you cannot update immediately, consider disabling or completely removing the plugin until a secure version is released. Regularly reviewing your WordPress site’s security posture and applying updates promptly can prevent such critical vulnerabilities from being exploited. For more general advice on securing your site, you might find our article on WordPress Security Best Practices helpful.
References
https://packetstormsecurity.com/files/131413/
https://packetstormsecurity.com/files/131514/
https://plugins.trac.wordpress.org/browser/website-contact-form-with-file-upload/trunk/readme.txt
https://plugins.trac.wordpress.org/browser/website-contact-form-with-file-upload/trunk/readme.txt#L147
https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-n-media-website-contact-form-with-file-upload-arbitrary-file-upload-1-3-4/
https://www.homelab.it/index.php/2015/04/12/wordpress-n-media-website-contact-form-shell-upload/
https://www.wordfence.com/threat-intel/vulnerabilities/id/8395e0c4-3feb-4551-9f2f-7b80cd187eca?source=cve


