Known CVE
Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload
The plugin does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE.
CVE-2023-4666
Critical2023CVSS 9.8
wpscan · cve2023 · wordpress · wp-plugin · form-maker · passive · vkev · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website