CVE-2024-28890: Malicious File Upload
Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive information by accessing files on the server, alter the site that uses the plugin, and cause a denial-of-service (DoS) condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28890?
CVE-2024-28890 is considered a critical vulnerability due to its potential for unrestricted file upload, leading to serious security risks.
How do I fix CVE-2024-28890?
To fix CVE-2024-28890, update the Forminator plugin to version 1.29.0 or later as it resolves the vulnerability.
What impact does CVE-2024-28890 have on my website?
CVE-2024-28890 can allow remote attackers to access sensitive files, alter your website, and potentially cause a denial-of-service.
Who is affected by CVE-2024-28890?
CVE-2024-28890 affects all versions of the Forminator plugin prior to 1.29.0, impacting over 300,000 WordPress sites.
Is it safe to use an older version of Forminator after CVE-2024-28890?
No, using an older version of Forminator poses significant security risks due to the vulnerabilities present in versions before 1.29.0.