CVE-2023-45603
WordPress User Submitted Posts Plugin <= 20230902 is vulnerable to Arbitrary File Upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Unrestricted Upload of File with Dangerous Type vulnerability in Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End.This issue affects User Submitted Posts – Enable Users to Submit Posts from the Front End: from n/a through 20230902.
Carga sin restricciones de archivos con vulnerabilidad de tipo peligroso en Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End. Este problema afecta a User Submitted Posts – Enable Users to Submit Posts from the Front End desde n/a hasta 20230902.
The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the usp_attach_images function in versions up to, and including, 20230902. This makes it possible for unauthenticatedattackers to upload arbitrary files as long as the extension does not contain 'php' on the affected site's server which may make remote code execution possible.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-10-09 CVE Reserved
- 2023-10-10 CVE Published
- 2023-10-15 First Exploit
- 2024-08-02 CVE Updated
- 2024-11-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (2)
URL | Date | SRC |
---|---|---|
https://github.com/codeb0ss/CVE-2023-45603-PoC | 2023-10-15 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Plugin-planet Search vendor "Plugin-planet" | User Submitted Posts Search vendor "Plugin-planet" for product "User Submitted Posts" | <= 20230902 Search vendor "Plugin-planet" for product "User Submitted Posts" and version " <= 20230902" | wordpress |
Affected
|