WordPress Piotnet Forms Plugin <= 1.0.25 is vulnerable to Arbitrary File Upload
CVE-2023-51412
9CRITICAL
Summary
The Piotnet Forms plugin for WordPress has a vulnerability that allows an unrestricted upload of files, potentially leading to the execution of malicious files on the server. This weakness allows attackers to upload harmful scripts, compromising the security of the affected site and exposing sensitive data. Users of Piotnet Forms versions from n/a through 1.0.25 should take immediate action to secure their installations and mitigate risks associated with this vulnerability.
Affected Version(s)
Piotnet Forms <= 1.0.25
References
CVSS V3.1
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)