Contact Form 7 REST API
-
Do Not Upgrade To Contact Form 7 4.8! Can Anyone suggest an easy way to revert to the previous tried and true version?
Contact Form 7 4.8 introduces the FormData object used to compose submission data and adds a couple of custom REST API endpoints that Ajax submissions are directed to.
The Couple of custom REST API’s introduce serious secuirty issues on WordPress Websites! and there is not an option in the plugin to enable or disable REST API so the update is NOT backward compatable!
Just Some of the Security Problems with REST API
REST API Security Issues
https://blog.sucuri.net/2017/02/content-injection-vulnerability-wordpress-rest-api.html
https://blog.sucuri.net/2017/02/content-injection-vulnerability-wordpress-rest-api.html
https://blog.sucuri.net/2017/02/wordpress-rest-api-vulnerability-abused-in-defacement-campaigns.html
https://blog.sucuri.net/2017/02/wordpress-rest-api-vulnerability-abused-in-defacement-campaigns.html
https://wptavern.com/wordpress-rest-api-vulnerability-exploits-continue
https://wptavern.com/wordpress-rest-api-vulnerability-exploits-continue
- The topic ‘Contact Form 7 REST API’ is closed to new replies.