Arbitrary File Upload Vulnerability Affects CRM Perks Forms Plugin
CVE-2024-7484
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 6 August 2024
Summary
The CRM Perks Forms plugin for WordPress has a vulnerability that allows authenticated users with administrator-level privileges to perform arbitrary file uploads. This vulnerability arises from inadequate validation of files in the 'handle_uploaded_files' function, present in versions up to and including 1.1.3. Successful exploitation of this vulnerability may enable attackers to upload malicious files to the server, creating potential pathways for remote code execution and other harmful actions. Proper validation mechanisms are essential to prevent unauthorized file access and maintain the security integrity of WordPress sites.
Affected Version(s)
CRM Perks Forms – WordPress Form Builder * <= 1.1.3
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved