The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged user to upload arbitrary files to the web server, triggering an RCE vulnerability by uploading a web shell.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 18 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-06-18T16:04:16.427Z
Reserved: 2023-11-03T17:40:53.323Z
Link: CVE-2023-5957
Updated: 2024-08-02T08:14:25.192Z
Status : Modified
Published: 2024-01-08T19:15:09.890
Modified: 2025-06-18T16:15:24.493
Link: CVE-2023-5957
No data.
OpenCVE Enrichment
No data.