The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows the operating system to execute commands and fully compromise the server on behalf of a user with Author-level privileges.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/6ad99725-eccc-4b61-bce2-668b62619deb | Exploit Third Party Advisory |
Configurations
History
08 Dec 2023, 15:02
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-94 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
References | () https://wpscan.com/vulnerability/6ad99725-eccc-4b61-bce2-668b62619debĀ - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:filr_project:filr:*:*:*:*:*:wordpress:*:* |
04 Dec 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-04 22:15
Updated : 2024-02-05 00:22
NVD link : CVE-2023-5762
Mitre link : CVE-2023-5762
CVE.ORG link : CVE-2023-5762
JSON object : View
Products Affected
filr_project
- filr
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')