Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder, CVE-2023-4666
- CVE, Research URL
- Home page URL
- Published on
- Oct 17, 2023
- Research Description
- The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE
- Affected versions
-
Min -, max 1.15.20.
- Status
-
vulnerable