The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'forminator_allowed_mime_types' function in versions up to, and including, 1.27.0. This makes it possible for authenticated attackers with administrator-level capabilities or above to upload arbitrary files on the affected site's server, but due to the htaccess configuration, remote code cannot be executed.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Wordfence

Published: 2023-11-15T06:40:46.339Z

Updated: 2023-11-15T06:40:46.339Z

Reserved: 2023-11-14T18:06:41.460Z


Link: CVE-2023-6133

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-15T07:15:14.837

Modified: 2023-11-30T14:52:31.180


Link: CVE-2023-6133

JSON object: View

cve-icon Redhat Information

No data.

CWE