Description
The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or validate the plugin URL in its functionality for installing add-ons. This allows a user with a role as low as Subscriber to install and activate arbitrary plugins of arbitrary versions from the WordPress.org plugin repository onto the site, leading to Remote Code Execution.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 03 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-12-03T17:00:58.356Z
Reserved: 2023-05-24T19:06:14.128Z
Link: CVE-2023-2877
Updated: 2024-08-02T06:41:02.359Z
Status : Modified
Published: 2023-06-27T14:15:11.633
Modified: 2024-11-21T07:59:28.710
Link: CVE-2023-2877
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.