The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2023-11-06T20:41:49.307Z

Updated: 2024-08-02T08:07:32.111Z

Reserved: 2023-10-16T11:56:41.635Z

Link: CVE-2023-5601

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-11-06T21:15:10.063

Modified: 2023-11-14T19:03:39.863

Link: CVE-2023-5601

cve-icon Redhat

No data.