// For flags

CVE-2023-2068

File Manager Advanced Shortcode <= 2.3.2 - Unauthenticated Remote Code Execution through shortcode

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.

The File Manager Advanced Shortcode WordPress plugin for WordPress is vulnerable to remote code execution in versions up to, and including, 2.3.2. This is due to the plugin allowing users to upload PHP files when the shortcode has been added to a page/post. This makes it possible for unauthenticated users to potentially upload malicious PHP files if the shortcode is used on the front-end of the site, and makes it possible for authenticated users with access to a post editor to add the shortcode to a page or post and subsequently upload a malicious file.

File Manager Advanced Shortcode version 2.3.2 suffers from a remote code execution vulnerability.

*Credits: Mateus Machado Tesser, WPScan
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-04-14 CVE Reserved
  • 2023-05-31 CVE Published
  • 2023-06-04 First Exploit
  • 2024-07-29 EPSS Updated
  • 2024-08-02 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Advancedfilemanager
Search vendor "Advancedfilemanager"
File Manager Advanced Shortcode
Search vendor "Advancedfilemanager" for product "File Manager Advanced Shortcode"
<= 2.3.2
Search vendor "Advancedfilemanager" for product "File Manager Advanced Shortcode" and version " <= 2.3.2"
wordpress
Affected