The Metform Elementor Contact Form Builder for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in versions up to, and including, 3.2.4. This allows unauthenticated visitors to perform a "double extension" attack and upload files containing a malicious extension but ending with a benign extension, which may make remote code execution possible in some configurations.
History

Mon, 19 Aug 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Wpmet
Wpmet metform Elementor Contact Form Builder
CPEs cpe:2.3:a:wpmet:metform_elementor_contact_form_builder:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpmet
Wpmet metform Elementor Contact Form Builder
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 17 Aug 2024 09:45:00 +0000

Type Values Removed Values Added
Description The Metform Elementor Contact Form Builder for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in versions up to, and including, 3.2.4. This allows unauthenticated visitors to perform a "double extension" attack and upload files containing a malicious extension but ending with a benign extension, which may make remote code execution possible in some configurations.
Title Metform Elementor Contact Form Builder <= 3.2.4 - Unauthenticated Double-Extension Arbitrary File Upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-08-17T09:38:58.449Z

Updated: 2024-08-19T18:19:24.186Z

Reserved: 2023-02-07T16:02:24.488Z

Link: CVE-2023-0714

cve-icon Vulnrichment

Updated: 2024-08-19T18:19:13.059Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-17T10:15:06.147

Modified: 2024-08-19T12:59:59.177

Link: CVE-2023-0714

cve-icon Redhat

No data.