The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/a8350890-e6d4-4b04-a158-2b0ee3748e65 | Exploit Third Party Advisory |
Configurations
History
27 Jun 2023, 09:05
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://wpscan.com/vulnerability/a8350890-e6d4-4b04-a158-2b0ee3748e65 - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:themepunch:slider_revolution:*:*:*:*:*:wordpress:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
19 Jun 2023, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-19 11:15
Updated : 2024-02-04 23:37
NVD link : CVE-2023-2359
Mitre link : CVE-2023-2359
CVE.ORG link : CVE-2023-2359
JSON object : View
Products Affected
themepunch
- slider_revolution
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')