Lucene search

K
nvd[email protected]NVD:CVE-2023-6133
HistoryNov 15, 2023 - 7:15 a.m.

CVE-2023-6133

2023-11-1507:15:14
CWE-434
web.nvd.nist.gov
1
forminator plugin
wordpress
arbitrary file uploads
blacklisting
authenticated attackers
administrator-level capabilities

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

31.8%

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the ‘forminator_allowed_mime_types’ function in versions up to, and including, 1.27.0. This makes it possible for authenticated attackers with administrator-level capabilities or above to upload arbitrary files on the affected site’s server, but due to the htaccess configuration, remote code cannot be executed.

Affected configurations

Nvd
Node
incsubforminatorRange1.27.0wordpress
VendorProductVersionCPE
incsubforminator*cpe:2.3:a:incsub:forminator:*:*:*:*:*:wordpress:*:*

CVSS3

4.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

EPSS

0.001

Percentile

31.8%