PT-2023-21696 · WordPress · Mw Wp Form

Taizoh Tsukamoto

·

Published

2023-05-23

·

Updated

2025-01-17

·

CVE-2023-28408

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MW WP Form versions v4.4.2 and earlier
Description A directory traversal vulnerability allows a remote unauthenticated attacker to alter the website or cause a denial-of-service (DoS) condition, and obtain sensitive information depending on settings.
Recommendations For MW WP Form versions v4.4.2 and earlier, update to a version later than v4.4.2 to resolve the issue. As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to prevent unauthorized alterations to the website.

Fix

DoS

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-28408

Affected Products

Mw Wp Form