CVE-2024-5084
The Hash Form β Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'file_upload_action' function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
- Affected products
- The Hash Form β Drag & Drop Form Builder
- Hashthemes Hash Form
- < 1.1.1
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 50.7% (99th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2024-05-23
CVE-2024-5084 at NVD
13 known exploits for CVE-2024-5084
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2024-5084
CVE-2024-5084-Red-Team
CVE-2024-5084
CVE-2024-5084
CVE-2024-5084
Exploit for Authentication Bypass by Spoofing in Booster Booster_For_Woocommerce
Exploit for Unrestricted Upload of File with Dangerous Type in Hashthemes Hash_Form
Exploit for Unrestricted Upload of File with Dangerous Type in Hashthemes Hash_Form
WordPress Hash Form 1.1.0 Remote Code Execution
WordPress Hash Form Plugin Remote Code Execution Exploit
Exploit for Unrestricted Upload of File with Dangerous Type in Hashthemes Hash_Form
Exploit for Unrestricted Upload of File with Dangerous Type in Hashthemes Hash_Form
WordPress Hash Form Plugin RCE