ZeroHour

CVE-2023-4238

PoC
CVSS 3.1
7.2 high
EPSS
2%p74
Published
()
Modified
Description

The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.

Vendors
miniorange
Products
prevent files \/ folders access
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.