Lucene search

K
cvelistWordfenceCVELIST:CVE-2023-6133
HistoryNov 15, 2023 - 6:40 a.m.

CVE-2023-6133

2023-11-1506:40:46
Wordfence
www.cve.org
1
wordpress
file uploads
security vulnerability
mime types
authentication
administrator.

CVSS3

6.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

31.8%

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the ‘forminator_allowed_mime_types’ function in versions up to, and including, 1.27.0. This makes it possible for authenticated attackers with administrator-level capabilities or above to upload arbitrary files on the affected site’s server, but due to the htaccess configuration, remote code cannot be executed.

CNA Affected

[
  {
    "vendor": "wpmudev",
    "product": "Forminator – Contact Form, Payment Form & Custom Form Builder",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "1.27.0",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

6.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

31.8%

Related for CVELIST:CVE-2023-6133