CVE Database
/

CVE-2024-28890

Back to search

CVE-2024-28890

Published: Apr 23, 2024

Modified: Nov 18, 2024

PUBLISHED

Description

Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive information by accessing files on the server, alter the site that uses the plugin, and cause a denial-of-service (DoS) condition.

VendorProductVersions

WPMU DEV

Forminator

affected
prior to 1.29.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now