CVE-2023-5601
WooCommerce Ninja Forms Product Add-ons < 1.7.1 - Unauthenticated Arbitrary File Upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.
El complemento WooCommerce Ninja Forms Product Add-ons para WordPress anterior a 1.7.1 no valida el archivo que se va a cargar, lo que permite que cualquier usuario no autenticado cargue archivos arbitrarios en el servidor, lo que lleva a RCE.
The WooCommerce Ninja Forms Product Add-ons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in an unknown function in versions up to, and including, 1.7.0. This makes it possible for un authenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-10-16 CVE Reserved
- 2023-10-16 CVE Published
- 2023-10-19 First Exploit
- 2024-08-02 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/codeb0ss/CVE-2023-5601-PoC | 2023-10-19 | |
https://wpscan.com/vulnerability/0035ec5e-d405-4eb7-8fe4-29dd0c71e4bc | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Atomicwebstrategy Search vendor "Atomicwebstrategy" | Woocommerce Ninja Forms Product Add-ons Search vendor "Atomicwebstrategy" for product "Woocommerce Ninja Forms Product Add-ons" | < 1.7.1 Search vendor "Atomicwebstrategy" for product "Woocommerce Ninja Forms Product Add-ons" and version " < 1.7.1" | wordpress |
Affected
|