CVE-2014-6446
The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 46.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 46.17% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- infusionsoft gravity forms project/infusionsoft gravity forms
- Source
- cve@mitre.org
References
- http://osvdb.org/show/osvdb/112171
- http://packetstormsecurity.com/files/131002/Wordpress-InfusionSoft-Shell-Upload.htmlExploit
- http://research.g0blin.co.uk/cve-2014-6446/Exploit
- http://www.exploit-db.com/exploits/34925Exploit
- https://wordpress.org/plugins/infusionsoft/changelog/Patch
- http://osvdb.org/show/osvdb/112171
- http://packetstormsecurity.com/files/131002/Wordpress-InfusionSoft-Shell-Upload.htmlExploit
- http://research.g0blin.co.uk/cve-2014-6446/Exploit
- http://www.exploit-db.com/exploits/34925Exploit
- https://wordpress.org/plugins/infusionsoft/changelog/Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.