The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.
History

Tue, 03 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-06-27T13:17:12.873Z

Updated: 2024-12-03T17:00:58.356Z

Reserved: 2023-05-24T19:06:14.128Z

Link: CVE-2023-2877

cve-icon Vulnrichment

Updated: 2024-08-02T06:41:02.359Z

cve-icon NVD

Status : Modified

Published: 2023-06-27T14:15:11.633

Modified: 2024-11-21T07:59:28.710

Link: CVE-2023-2877

cve-icon Redhat

No data.