Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-2877

Опубликовано: 27 июн. 2023
Источник: nvd
CVSS3: 8.8
EPSS Средний

Описание

The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:strategy11:formidable_forms:*:*:*:*:*:wordpress:*:*
Версия до 6.3.1 (исключая)

EPSS

Процентиль: 99%
0.68996
Средний

8.8 High

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 8.8
github
больше 2 лет назад

The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.

EPSS

Процентиль: 99%
0.68996
Средний

8.8 High

CVSS3

Дефекты