cleantalk
Vulnerabilities and Security Researches

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder, CVE-2023-4666

CVE, Research URL

CVE-2023-4666

Published on
Oct 17, 2023
Research Description
The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE
Affected versions
Min -, max 1.15.20.
Status
vulnerable