Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-4596
HistoryAug 30, 2023 - 2:15 a.m.

Input validation

2023-08-3002:15:00
PRIOn knowledge base
www.prio-n.com
4
forminator
wordpress
plugin
arbitrary file uploads
file type validation
remote code execution
security vulnerability
nvd

9.8 High

AI Score

Confidence

High

0.106 Low

EPSS

Percentile

95.1%

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site’s server which may make remote code execution possible.

CPENameOperatorVersion
forminatorle1.24.6

9.8 High

AI Score

Confidence

High

0.106 Low

EPSS

Percentile

95.1%