The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary files such as PHP on the server
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2023-12-26T18:33:01.473Z
Updated: 2024-08-02T08:14:25.118Z
Reserved: 2023-11-02T13:39:26.334Z
Link: CVE-2023-5931
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-12-26T19:15:08.077
Modified: 2024-11-21T08:42:48.403
Link: CVE-2023-5931
Redhat
No data.