The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2023-08-30T01:45:37.073Z
Updated: 2024-08-02T07:31:06.579Z
Reserved: 2023-08-29T13:03:40.119Z
Link: CVE-2023-4596
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-08-30T02:15:09.353
Modified: 2024-11-21T08:35:30.643
Link: CVE-2023-4596
Redhat
No data.