ZeroHour

CVE-2023-2688

CVSS 3.1
4.9 medium
EPSS
2%p76
Published
()
Modified
Description

The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level attackers to move files uploaded with the plugin (located in wp-content/uploads by default) outside of the web root.

Vendors
iptanus
Products
wordpress file upload, wordpress file upload pro
Ecosystems
WordPress
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.