The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE
We have discovered 8,201 live websites that are affected by CVE-2023-4666.
Product | |
Category | Form Builders |
Vulnerable Domains | 8,201 live websites (57.66% of Form Maker install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 249 versions ( 56.33% of all versions) |
![]() | 3,288 websites |
![]() | 879 websites |
![]() | 406 websites |
![]() | 340 websites |
![]() | 333 websites |
![]() | 226 websites |
![]() | 191 websites |
![]() | 164 websites |
![]() | 163 websites |
![]() | 142 websites |
.com | 3,426 websites |
.org | 669 websites |
.de | 409 websites |
.nl | 316 websites |
.co.uk | 212 websites |
.net | 207 websites |
.it | 186 websites |
.ru | 176 websites |
.fr | 131 websites |
.com.br | 130 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.com | ![]() | *,*** | |
********.nl | ![]() | ***,*** | |
******.com | ![]() | ***,*** | |
*****.eu | ![]() | ***,*** | |
****************.org | ![]() | ***,*** | |
****************.org | ![]() | ***,*** | |
******************.org | ![]() | ***,*** | |
******************.com | ![]() | ***,*** | |
****.it | ![]() | ***,*** | |
*******.org | ![]() | ***,*** |
FAQ