First published: Tue Apr 23 2024(Updated: )
Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive information by accessing files on the server, alter the site that uses the plugin, and cause a denial-of-service (DoS) condition.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Forminator | <1.29.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28890 is considered a critical vulnerability due to its potential for unrestricted file upload, leading to serious security risks.
To fix CVE-2024-28890, update the Forminator plugin to version 1.29.0 or later as it resolves the vulnerability.
CVE-2024-28890 can allow remote attackers to access sensitive files, alter your website, and potentially cause a denial-of-service.
CVE-2024-28890 affects all versions of the Forminator plugin prior to 1.29.0, impacting over 300,000 WordPress sites.
No, using an older version of Forminator poses significant security risks due to the vulnerabilities present in versions before 1.29.0.