CVE-2023-6133

Severity
4.9MEDIUM
EPSS
0.3%
top 50.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 15
Latest updateApr 11

Description

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'forminator_allowed_mime_types' function in versions up to, and including, 1.27.0. This makes it possible for authenticated attackers with administrator-level capabilities or above to upload arbitrary files on the affected site's server, but due to the htaccess configuration, remote code cannot be executed.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.7 | Impact: 5.9

Affected Packages1 packages

NVDincsub/forminator1.27.0

Patches

🔴Vulnerability Details

3
VulDB
Forminator Plugin up to 1.27.0 on WordPress unrestricted upload (ID 2995007)2026-04-11
GHSA
GHSA-9w33-c6rh-4qfg: The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient blacklisting on the 'forminator_allowed_mime_types' fu2023-11-15
CVEList
Forminator <= 1.27.0 - Authenticated (Administrator+) Arbitrary File Upload2023-11-15
CVE-2023-6133 (MEDIUM CVSS 4.9) | The Forminator plugin for WordPress | cvebase.io