CVE-2023-4666
The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE
- Affected products
- The Form Maker
- 10web Form Maker
- < 1.15.20
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 3.3% (87th percentile)
- NVD status
- Modified
- Published
- 2023-10-16
CVE-2023-4666 at NVD
2 known exploits for CVE-2023-4666
Proof-of-concept code and exploit modules indexed by Sploitus