CVE-2023-4666
Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload
Record summary
CVE-2023-4666 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 7, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
form_makerBrowse 10web / form_maker | VulnCheck | Version data not supplied | |
Form Maker by 10WebDefault status: unaffected | CVE List | Before 1.15.20 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALForm-Maker < 1.15.20 - Unauthenticated Arbitrary File UploadCVSS 9.8
The plugin does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE.
Impact
Unauthenticated attackers can exploit missing signature validation to upload arbitrary files and achieve remote code execution on WordPress installations running vulnerable Form-Maker plugins.
Remediation
Fixed in 1.15.20
Source: ProjectDiscovery