PT-2023-30146 · 10Web · The Form Maker

·

CVE-2023-4666

·

Published

2023-10-16

·

Updated

2025-09-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Form Maker by 10Web WordPress plugin versions prior to 1.15.20
Description The issue allows unauthenticated users to create arbitrary files on the server from user input due to a lack of signature validation, potentially leading to remote code execution (RCE).
Recommendations For versions prior to 1.15.20, update to version 1.15.20 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's file creation functionality until a patch is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-4666

Affected Products

The Form Maker