id: CVE-2023-4666 info: name: Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload author: pussycat0x severity: critical description: | The plugin does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE. impact: | Unauthenticated attackers can exploit missing signature validation to upload arbitrary files and achieve remote code execution on WordPress installations running vulnerable Form-Maker plugins. remediation: Fixed in 1.15.20 reference: - https://wpscan.com/vulnerability/c6597e36-02d6-46b4-89db-52c160f418be/ classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2023-4666 epss-score: 0.03283 epss-percentile: 0.87144 cpe: cpe:2.3:a:10web:form_maker:*:*:*:*:*:wordpress:*:* metadata: verified: true fofa-query: 'body="/wp-content/plugins/form-maker/"' max-request: 1 vendor: 10web product: form_maker framework: wordpress tags: wpscan,cve,cve2023,wordpress,wp-plugin,form-maker,passive,vkev,vuln http: - method: GET path: - "{{BaseURL}}/wp-content/plugins/form-maker/readme.txt" matchers-condition: and matchers: - type: dsl dsl: - "status_code == 200" - "compare_versions(version, '< 1.15.20')" - "contains(body, 'Form Maker by 10Web')" condition: and extractors: - type: regex part: body group: 1 name: version regex: - 'Stable tag: ([0-9.]+)' internal: true # digest: 490a00463044022018bfbb6582295adabb60015ad05b90e46e993926958bbf589ce75f1c8ff1aead02201a093207376912bdcd1b759182891cccc1d288abe53e1769e9957dba50c141c0:922c64590222798bb761d5b6d8e72950