10

CVE-2024-51791

WordPress Forms plugin <= 2.8.0 - Arbitrary File Upload vulnerability

Forms <= 2.8.0 - Unauthenticated Arbitrary File Upload

Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms forms-by-made-it allows Upload a Web Shell to a Web Server.This issue affects Forms: from n/a through <= 2.8.0.
Mögliche Gegenmaßnahme
Forms: Update to version 2.8.1, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellermadeit
Produkt forms
Default Statusunknown
Version <= 2.8.0
Version 0
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Forms
Version *-2.8.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.61% 0.444
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
audit@patchstack.com 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://github.com/JoshuaProvoste/0-click-RCE-Exploit-for-CVE-2024-51791
https://patchstack.com/database/Wordpress/Plugin/forms-by-made-it/vulnerability/wordpress-forms-plugin-2-8-0-arbitrary-file-upload-vulnerability?_s_id=cve
https://www.wordfence.com/threat-intel/vulnerabilities/id/06dfc3da-6f61-433c-a1e1-48749b654fcd
Third Party Advisory