cleantalk
Vulnerabilities and Security Researches

Essential Real Estate, CVE-2023-6827

CVE, Research URL

CVE-2023-6827

Application

Essential Real Estate

Published on
Dec 15, 2023
Research Description
The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'ajaxUploadFonts' function in versions up to, and including, 4.3.5. This makes it possible for authenticated attackers with subscriber-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected versions
Min -, max 4.4.0.
Status
vulnerable