ZeroHour

CVE-2023-5673

PoC
CVSS 3.1
8.8 high
EPSS
1%p64
Published
()
Modified
Description

The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to emails, allowing attackers to upload PHP files, leading to remote code execution.

Vendors
wpvibes
Products
wp mail log
Ecosystems
WordPress
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.