The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/a8350890-e6d4-4b04-a158-2b0ee3748e65 | Exploit Third Party Advisory |
https://wpscan.com/vulnerability/a8350890-e6d4-4b04-a158-2b0ee3748e65 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 07:58
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/a8350890-e6d4-4b04-a158-2b0ee3748e65 - Exploit, Third Party Advisory |
27 Jun 2023, 09:05
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://wpscan.com/vulnerability/a8350890-e6d4-4b04-a158-2b0ee3748e65 - Exploit, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
First Time |
Themepunch
Themepunch slider Revolution |
|
CPE | cpe:2.3:a:themepunch:slider_revolution:*:*:*:*:*:wordpress:*:* |
19 Jun 2023, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-19 11:15
Updated : 2024-11-21 07:58
NVD link : CVE-2023-2359
Mitre link : CVE-2023-2359
CVE.ORG link : CVE-2023-2359
JSON object : View
Products Affected
themepunch
- slider_revolution
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')