CVE-2023-4666
Summary
| CVE | CVE-2023-4666 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-16 20:15:00 UTC |
| Updated | 2023-11-07 04:22:00 UTC |
| Description | The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
10web |
Form Maker |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload WordPress Security Vulnerability |
MISC |
wpscan.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.