WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows unauthenticated attackers to upload and execute arbitrary PHP files. Attackers can send POST requests to the connector.minimal.php endpoint with mkfile and put commands to create malicious PHP files in the file_manager directory and execute them on the server.
History

Mon, 08 Jun 2026 02:00:00 +0000

Type Values Removed Values Added
Description WordPress Augmented-Reality plugin contains a remote code execution vulnerability in the elFinder connector that allows unauthenticated attackers to upload and execute arbitrary PHP files. Attackers can send POST requests to the connector.minimal.php endpoint with mkfile and put commands to create malicious PHP files in the file_manager directory and execute them on the server.
Title WordPress Augmented-Reality Plugin Remote Code Execution Unauthenticated
First Time appeared Webandprint
Webandprint ar
Weaknesses CWE-306
CPEs cpe:2.3:a:webandprint:ar:7.0:*:*:*:*:wordpress:*:*
Vendors & Products Webandprint
Webandprint ar
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-06-08T01:55:28.450Z

Updated: 2026-06-08T01:55:28.450Z

Reserved: 2026-01-10T01:51:52.987Z

Link: CVE-2023-54350

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-06-08T02:16:22.810

Modified: 2026-06-08T14:59:44.750

Link: CVE-2023-54350

cve-icon Redhat

No data.