CVE · Critical

CVE-2023-0714 — MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor [metform] < 3.3.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-0714 MetForm – Contact Form, Survey, Quiz, Conditional Forms, Form Templates & Custom Form Builder for Elementor [metform] < 3.3.0 Unrestricted Upload of File with Dangerous Type Critical 9.8 < 3.3.0 3.3.0 2024-08-16

CVE-2023-0714

The MetForm contact form builder plugin for Elementor contains a file upload vulnerability in versions through 3.2.4 where insufficient validation of file types permits unauthenticated users to upload arbitrary files. Attackers can exploit this by using double extension techniques to bypass checks, uploading files with dangerous extensions disguised with harmless ones at the end. Depending on server configuration, this could enable remote code execution. The vulnerability was patched in version 3.3.0.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.