The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 03 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-12-03T17:00:58.356Z
Reserved: 2023-05-24T19:06:14.128Z
Link: CVE-2023-2877
Updated: 2024-08-02T06:41:02.359Z
Status : Modified
Published: 2023-06-27T14:15:11.633
Modified: 2024-11-21T07:59:28.710
Link: CVE-2023-2877
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.