The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'forminator_allowed_mime_types' function in versions up to, and including, 1.27.0. This makes it possible for authenticated attackers with administrator-level capabilities or above to upload arbitrary files on the affected site's server, but due to the htaccess configuration, remote code cannot be executed.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2023-11-15T06:40:46.339Z

Updated: 2024-08-02T08:21:17.396Z

Reserved: 2023-11-14T18:06:41.460Z

Link: CVE-2023-6133

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-11-15T07:15:14.837

Modified: 2023-11-30T14:52:31.180

Link: CVE-2023-6133

cve-icon Redhat

No data.