The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/c6597e36-02d6-46b4-89db-52c160f418be | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/c6597e36-02d6-46b4-89db-52c160f418be | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 08:35
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/c6597e36-02d6-46b4-89db-52c160f418be - Exploit, Third Party Advisory |
07 Nov 2023, 04:22
Type | Values Removed | Values Added |
---|---|---|
CWE |
20 Oct 2023, 16:53
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:10web:form_maker:*:*:*:*:*:wordpress:*:* | |
References | (MISC) https://wpscan.com/vulnerability/c6597e36-02d6-46b4-89db-52c160f418be - Exploit, Third Party Advisory | |
First Time |
10web
10web form Maker |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
16 Oct 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-16 20:15
Updated : 2024-11-21 08:35
NVD link : CVE-2023-4666
Mitre link : CVE-2023-4666
CVE.ORG link : CVE-2023-4666
JSON object : View
Products Affected
10web
- form_maker
CWE
No CWE.