Lucene search

K
cveWordfenceCVE-2023-6133
HistoryNov 15, 2023 - 7:15 a.m.

CVE-2023-6133

2023-11-1507:15:14
CWE-434
Wordfence
web.nvd.nist.gov
15
forminator
wordpress
cve-2023-6133
file upload
vulnerability
nvd

CVSS3

6.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

31.8%

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the ‘forminator_allowed_mime_types’ function in versions up to, and including, 1.27.0. This makes it possible for authenticated attackers with administrator-level capabilities or above to upload arbitrary files on the affected site’s server, but due to the htaccess configuration, remote code cannot be executed.

Affected configurations

Nvd
Vulners
Node
incsubforminatorRange1.27.0wordpress
VendorProductVersionCPE
incsubforminator*cpe:2.3:a:incsub:forminator:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "wpmudev",
    "product": "Forminator – Contact Form, Payment Form & Custom Form Builder",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "1.27.0",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

6.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

31.8%