WordPress Plugin Vulnerabilities

Forminator < 1.28.0 - Admin+ Arbitrary File Upload

Description

The plugin does not properly blacklist files via the forminator_allowed_mime_types function, which could allow administrator to upload arbitrary file. However, RCE can not be achieved due to htaccess configuration.

Affects Plugins

Fixed in 1.28.0

References

Miscellaneous

Original Researcher
István Márton
Verified
No

Timeline

Publicly Published
2023-11-14 (about 2 years ago)
Added
2023-11-15 (about 2 years ago)
Last Updated
2023-11-15 (about 2 years ago)

Other