The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.
History

Wed, 27 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-06-27T13:17:19.200Z

Updated: 2024-11-27T19:20:56.044Z

Reserved: 2023-04-14T14:53:15.771Z

Link: CVE-2023-2068

cve-icon Vulnrichment

Updated: 2024-08-02T06:12:19.937Z

cve-icon NVD

Status : Modified

Published: 2023-06-27T14:15:10.477

Modified: 2024-11-21T07:57:52.570

Link: CVE-2023-2068

cve-icon Redhat

No data.