The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
https://www.jinsonvarghese.com/unrestricted-file-upload-in-contact-form-7/
https://www.getastra.com/blog/911/plugin-exploit/contact-form-7-unrestricted-file-upload/
https://wpscan.com/vulnerability/10508
https://wordpress.org/plugins/contact-form-7/#developers
https://contactform7.com/2020/12/17/contact-form-7-532/
Source: Mitre, NVD
Published: 2020-12-17
Updated: 2020-12-22
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS: 0.9037