vendor:
Forminator
by:
Mehmet Kelepçe
9.8
CVSS
CRITICAL
Unauthenticated Remote Command Execution
78
CWE
Product Name: Forminator
Affected Version From: 1.24.6
Affected Version To: 1.24.6
Patch Exists: NO
Related CWE:
CPE: a:wpmudev:forminator:1.24.6
Platforms Tested: Windows 11
2023
WordPress Plugin Forminator 1.24.6 – Unauthenticated Remote Command Execution
This exploit allows an attacker to execute remote commands without authentication in the WordPress Plugin Forminator version 1.24.6. The vulnerability is due to improper handling of user input in the 'postdata-1-post-image' parameter, which can be exploited to execute arbitrary PHP code.
Mitigation:
To mitigate this vulnerability, it is recommended to update to the latest version of the Forminator plugin.