T
he Enable Media Replace WordPress plugin before 4.0.2 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/b0239208-1e23-4774-9b8c-9611704a07a0 | Exploit Third Party Advisory |
| https://wpscan.com/vulnerability/b0239208-1e23-4774-9b8c-9611704a07a0 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 07:36
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://wpscan.com/vulnerability/b0239208-1e23-4774-9b8c-9611704a07a0 - Exploit, Third Party Advisory | |
| Summary |
|
Information
Published : 2023-02-13 15:15
Updated : 2025-03-21 16:15
NVD link : CVE-2023-0255
Mitre link : CVE-2023-0255
CVE.ORG link : CVE-2023-0255
JSON object : View
Products Affected
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type