Unrestricted upload of file with dangerous type exists in MW WP Form versions v4.4.2 and earlier, which may allow a remote unauthenticated attacker to upload an arbitrary file.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://plugins.2inc.org/mw-wp-form/blog/2023/05/08/752/ | vendor advisory |
https://jvn.jp/en/jp/JVN01093915/ | third party advisory |