The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files disguised as ZIP archives, which may lead to remote code execution.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-01-08T19:00:36.658Z
Updated: 2024-09-04T15:36:41.937Z
Reserved: 2023-11-14T22:50:43.564Z
Link: CVE-2023-6140
Vulnrichment
Updated: 2024-08-02T08:21:17.679Z
NVD
Status : Modified
Published: 2024-01-08T19:15:10.027
Modified: 2024-11-21T08:43:13.170
Link: CVE-2023-6140
Redhat
No data.