← Back to browse · API

CVE-2023-28408

Severity
CRITICAL
CVSS
9.8
EPSS
0.01776
Risk score
39.82
CISA KEV
No
PoC
No
Published
2023-05-23
Modified
2025-01-17
First seen
2026-08-07
Aliases
EUVD-2023-32104, GHSA-3Q42-588X-M4GV
Products
websoudan:MW WP Form versions v4.4.2 and earlier
Sources
euvd EUVD-2023-32104

Description

Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to alter the website or cause a denial-of-service (DoS) condition, and obtain sensitive information depending on settings.

References