ZeroHour

CVE-2023-2359

PoC
CVSS 3.1
8.8 high
EPSS
3%p84
Published
()
Modified
Description

The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.

Vendors
themepunch
Products
slider revolution
Ecosystems
WordPress
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.