CVE-2023-4238

The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:miniorange:prevent_files_\/_folders_access:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 08:34

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/53816136-4b1a-4b7d-b73b-08a90c2a638f - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/53816136-4b1a-4b7d-b73b-08a90c2a638f - Exploit, Third Party Advisory

07 Nov 2023, 04:22

Type Values Removed Values Added
CWE CWE-434

26 Sep 2023, 14:44

Type Values Removed Values Added
First Time Miniorange
Miniorange prevent Files \/ Folders Access
References (MISC) https://wpscan.com/vulnerability/53816136-4b1a-4b7d-b73b-08a90c2a638f - (MISC) https://wpscan.com/vulnerability/53816136-4b1a-4b7d-b73b-08a90c2a638f - Exploit, Third Party Advisory
CPE cpe:2.3:a:miniorange:prevent_files_\/_folders_access:*:*:*:*:*:wordpress:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

25 Sep 2023, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-25 16:15

Updated : 2024-11-21 08:34


NVD link : CVE-2023-4238

Mitre link : CVE-2023-4238

CVE.ORG link : CVE-2023-4238


JSON object : View

Products Affected

miniorange

  • prevent_files_\/_folders_access
CWE

No CWE.