CVE Database /
CVE-2023-0714
CVE · Critical
CVE-2023-0714 — MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor [metform] < 3.3.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-0714
|
MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor [metform] < 3.3.0 |
Unrestricted Upload of File with Dangerous Type |
Critical
9.8
|
< 3.3.0
|
3.3.0 |
2024-08-16 |
—
|
CVE-2023-0714
The MetForm contact form builder plugin for Elementor contains a file upload vulnerability in versions through 3.2.4 where insufficient validation of file types permits unauthenticated users to upload arbitrary files. Attackers can exploit this by using double extension techniques to bypass checks, uploading files with dangerous extensions disguised with harmless ones at the end. Depending on server configuration, this could enable remote code execution. The vulnerability was patched in version 3.3.0.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings