CVE-2023-48290: WordPress Form Maker by 10Web plugin <= 1.15.20 - Captcha Bypass Vulnerability vulnerability
Published Jun 4, 2024
·Updated
Improper Restriction of Excessive Authentication Attempts vulnerability in 10Web Form Builder Team Form Maker by 10Web allows Functionality Bypass.This issue affects Form Maker by 10Web: from n/a through 1.15.20.
Affected Software
3 affected components
10web Form Maker<=1.15.20
10web WordPress Form Maker<=1.15.20
10web Form Maker Wordpress<1.15.21
Remediation
Information
Update to 1.15.21 or a higher version.
Event History
Jun 4, 2024
CVE Published
via MITRE·10:25 AM
Data Sourced
via MITRE·10:25 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-48290?
The severity of CVE-2023-48290 is classified based on the potential for functionality bypass due to improper restriction of excessive authentication attempts.
2
How do I fix CVE-2023-48290?
To fix CVE-2023-48290, update 10Web Form Maker to the latest version beyond 1.15.20.
3
What versions of Form Maker are affected by CVE-2023-48290?
CVE-2023-48290 affects Form Maker by 10Web versions up to and including 1.15.20.
4
What type of vulnerability is CVE-2023-48290?
CVE-2023-48290 is an improper restriction of excessive authentication attempts vulnerability.
5
Can CVE-2023-48290 be exploited remotely?
Yes, CVE-2023-48290 can be exploited remotely, allowing attackers to bypass authentication mechanisms.