The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/c6597e36-02d6-46b4-89db-52c160f418be | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/c6597e36-02d6-46b4-89db-52c160f418be | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 08:35
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-16 20:15
Updated : 2024-11-21 08:35
NVD link : CVE-2023-4666
Mitre link : CVE-2023-4666
CVE.ORG link : CVE-2023-4666
JSON object : View
Products Affected
10web
- form_maker
CWE
No CWE.