CVE-2023-44227
WordPress Simple File List Plugin <= 6.1.9 is vulnerable to Arbitrary File Deletion
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
Missing Authorization vulnerability in Mitchell Bennis Simple File List.This issue affects Simple File List: from n/a through 6.1.9.
Vulnerabilidad de falta de autorizaciĆ³n en Mitchell Bennis Simple File List. Este problema afecta a Simple File List: desde n/a hasta 6.1.9.
The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including, 6.1.9. This is due to insufficient controls on files passed to a deletion function. This makes it possible for unauthenticated attackers to delete arbitrary files, which can lead to a denial of service or remote code execution when the wp-config.php file is deleted.
*Credits:
Rafshanzani Suhada (Patchstack Alliance)
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-09-27 CVE Reserved
- 2023-09-28 CVE Published
- 2023-10-19 First Exploit
- 2024-04-18 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-862: Missing Authorization
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/simple-file-list/wordpress-simple-file-list-plugin-6-1-8-arbitrary-file-deletion?_s_id=cve | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://github.com/codeb0ss/CVE-2023-44227-PoC | 2023-10-19 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Simple File List Search vendor "Simple File List" | Simple File List Search vendor "Simple File List" for product "Simple File List" | >= 0.0.0 <= 6.1.9 Search vendor "Simple File List" for product "Simple File List" and version " >= 0.0.0 <= 6.1.9" | en |
Affected
|