CVE-2024-5084: Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fileuploadaction' function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5084?
CVE-2024-5084 has a high severity due to its potential for arbitrary file uploads by unauthenticated attackers.
How do I fix CVE-2024-5084?
To fix CVE-2024-5084, update the Hash Form – Drag & Drop Form Builder plugin to version 1.1.1 or later.
Who is affected by CVE-2024-5084?
CVE-2024-5084 affects all versions of the Hash Form – Drag & Drop Form Builder plugin up to and including version 1.1.0.
What type of attacks can be performed using CVE-2024-5084?
Using CVE-2024-5084, attackers can upload arbitrary files, potentially leading to further exploitation of the vulnerable site.
Is authentication required to exploit CVE-2024-5084?
No, CVE-2024-5084 can be exploited by unauthenticated users, making it particularly dangerous.