CVE-2024-51791
About
Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms forms-by-made-it allows Upload a Web Shell to a Web Server.This issue affects Forms: from n/a through <= 2.8.0.
Rainforest analyst review
Made I.T. Forms permits an unrestricted file upload whose stated purpose is dropping a web shell onto the server, and it's reachable without any authentication. One crafted request can therefore plant executable code, and a web shell is full control of the site: the attacker can read the database, deface content, or use the box as a pivot into the hosting environment.
With no login to defeat and a maximum 10.0 score on a distributable WordPress plugin, this fits the exact template that mass-scanning campaigns automate. Unauthenticated upload-to-shell bugs get commodity exploitation quickly because the technique generalizes and the reward is total; every reachable install is a candidate the moment the details circulate.
As always with WordPress, the challenge is visibility rather than understanding — plugins are installed site-by-site and seldom inventoried centrally. Our focus is enumerating which sites run Made I.T. Forms and at what version, and confirming whether the upload path is exposed to the internet. This is a second unauthenticated web-shell plugin in this very batch, which reinforces that our standing WordPress inventory-and-patch discipline is what actually keeps these off the board, not one-off responses.
References
Related CVEs
Frequently asked questions
What is CVE-2024-51791?
Unrestricted Upload of File with Dangerous Type vulnerability in Made I.T. Forms forms-by-made-it allows Upload a Web Shell to a Web Server.This issue affects Forms: from n/a through <= 2.8.0.
How severe is CVE-2024-51791?
CVE-2024-51791 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.
How is CVE-2024-51791 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
How do I fix CVE-2024-51791?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
