WordPress File Upload, CVE-2023-2688
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jun 09, 2023
- Research Description
- The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level attackers to move files uploaded with the plugin (located in wp-content/uploads by default) outside of the web root.
- Affected versions
-
Min -, max 4.23.3.
- Status
-
vulnerable