[Japanese] | |
JVNDB-2023-012042 | |
WordPress plugin "MW WP Form" vulnerable to arbitrary file upload | |
Overview | |
WordPress plugin "MW WP Form" provided by Web Consultation Office Co., Ltd can create a mail form using shortcode. MW WP Form contains a vulnerability that may allow an attacker to upload arbitrary files (CVE-2023-6316, CWE-434). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 9.8 (Critical) [Other]
| |
Affected Products | |
| |
Web Consultation Office Co., Ltd | |
| |
Impact | |
When the "Saving inquiry data in database" option in the form settings is enabled, an attacker may execute arbitrary code on the server by uploading an arbitrary file. | |
Solution | |
[Update the plugin] | |
Vendor Information | |
Web Consultation Office Co., Ltd | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2023/12/14 |
Date First Published | 2023/12/15 |
Date Last Updated | 2024/03/26 |