cleantalk
Vulnerabilities and Security Researches

MW WP Form, CVE-2023-28409

CVE, Research URL

CVE-2023-28409

Application

MW WP Form

Published on
May 23, 2023
Research Description
Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file.
Affected versions
max 4.4.3.
Status
vulnerable