CVE-2023-4666

Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload

The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE


We have discovered 8,201 live websites that are affected by CVE-2023-4666.

Test my site




Affected Software

Product  Form Maker
Category Form Builders
Vulnerable Domains8,201 live websites (57.66% of Form Maker install base)
Vulnerable Versions
  • from 0 before 1.15.20
Vulnerable Versions Count249 versions ( 56.33% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Oct 16, 2023
  • Updated - Aug 2, 2024

Credits

  • dc11 (finder)
  • WPScan (coordinator)

CVE-2023-4666 usage by Country

United States3,288 websites



Germany879 websites
France406 websites
GB340 websites
Netherlands333 websites
Italy226 websites
Russia191 websites
Denmark164 websites
Canada163 websites
Switzerland142 websites

CVE-2023-4666 usage by TLD

.com3,426 websites
.org669 websites
.de409 websites
.nl316 websites
.co.uk212 websites
.net207 websites
.it186 websites
.ru176 websites
.fr131 websites
.com.br130 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-4666

Top websites that are affected by CVE-2023-4666. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States*,***
********.nl Netherlands***,***
******.com United States***,***
*****.eu Slovenia***,***
****************.org United States***,***
****************.org United States***,***
******************.org United States***,***
******************.com United States***,***
****.it Italy***,***
*******.org United States***,***
See full domain list

FAQ

CVE-2023-4666 is Unrestricted Upload of File with Dangerous Type in Form Maker
A total of 8,201 websites have been identified as vulnerable to CVE-2023-4666, discovered through global website indexing conducted by WebTechSurvey.
Form Maker is susceptible to CVE-2023-4666 vulnerability.
Form Maker versions before 1.15.20 are vulnerable to CVE-2023-4666.
Version 1.15.20 of Form Maker addresses the CVE-2023-4666 security vulnerability.