QID 150775
Date Published: 2024-01-17
QID 150775: WordPress MW WP Form Plugin: Unauthenticated Arbitrary File Upload Vulnerability (CVE-2023-6316)
MW WP Form is shortcode base contact form plugin.
The MW WP Form plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the '_single_file_upload' function. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Versions:
WordPress MW WP Form Plugin before 5.0.2.
QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation of this vulnerability could allow an unauthenticated attacker to attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- MW WP Form -
wordpress.org/plugins/mw-wp-form/#developers
CVEs related to QID 150775
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| MW WP Form |
|