ZeroHour

CVE-2023-5601

PoC
CVSS 3.1
9.8 critical
EPSS
<1%p57
Published
()
Modified
Description

The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.

Vendors
atomicwebstrategy
Products
woocommerce ninja forms product add-ons
Ecosystems
WordPress, E-commerce
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.