Логотип exploitDog
bind:CVE-2023-6140
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-6140

Количество 2

Количество 2

nvd логотип

CVE-2023-6140

около 2 лет назад

The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files disguised as ZIP archives, which may lead to remote code execution.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-pmx3-5c86-vxfm

около 2 лет назад

The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files disguised as ZIP archives, which may lead to remote code execution.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-6140

The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files disguised as ZIP archives, which may lead to remote code execution.

CVSS3: 8.8
4%
Низкий
около 2 лет назад
github логотип
GHSA-pmx3-5c86-vxfm

The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files disguised as ZIP archives, which may lead to remote code execution.

CVSS3: 8.8
4%
Низкий
около 2 лет назад

Уязвимостей на страницу