Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-4620

Опубликовано: 07 июн. 2024
Источник: nvd
CVSS3: 9.8
EPSS Высокий

Описание

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:reputeinfosystems:arforms:*:*:*:*:*:wordpress:*:*
Версия до 6.6 (исключая)

EPSS

Процентиль: 99%
0.72422
Высокий

9.8 Critical

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 9.8
github
больше 1 года назад

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP code can be uploaded when an upload file input is included on a form

EPSS

Процентиль: 99%
0.72422
Высокий

9.8 Critical

CVSS3

Дефекты

NVD-CWE-noinfo