Unrestricted File Upload Vulnerability in Made I.T. Forms Affects Web Servers
CVE-2025-24775
9.9CRITICAL
What is CVE-2025-24775?
The Made I.T. Forms plugin is susceptible to an unrestricted file upload vulnerability, enabling attackers to upload malicious files, such as web shells, to the web server. This flaw affects all versions up to 2.9.0, thereby posing significant security risks for websites utilizing the plugin. It is crucial for users to apply security updates immediately to mitigate the potential for exploitation.
Affected Version(s)
Forms <= 2.9.0