Record summary

CVE-2023-4666 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 7, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Form Maker by 10Web

Default status: unaffected

CVE ListBefore 1.15.20affected

Nuclei templates

1
ProjectDiscoveryCRITICALForm-Maker < 1.15.20 - Unauthenticated Arbitrary File UploadCVSS 9.8

The plugin does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE.

Impact

Unauthenticated attackers can exploit missing signature validation to upload arbitrary files and achieve remote code execution on WordPress installations running vulnerable Form-Maker plugins.

Remediation

Fixed in 1.15.20

Authorspussycat0x
Template tagswpscancvecve2023wordpresswp-pluginform-makerpassivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:10web:form_maker:*:*:*:*:*:wordpress:*:*
FOFA: body="/wp-content/plugins/form-maker/"

Source: ProjectDiscovery

References

2