The plugin does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE.
id: CVE-2023-4666
info:
name: Form-Maker < 1.15.20 - Unauthenticated Arbitrary File Upload
auth
...