Skip to content

Known CVE

Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload

The plugin does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE.

CVE-2023-4666

Critical2023CVSS 9.8

wpscan · cve2023 · wordpress · wp-plugin · form-maker · passive · vkev · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website