The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2023-11-06T20:41:49.307Z

Updated: 2023-11-06T20:41:49.307Z

Reserved: 2023-10-16T11:56:41.635Z


Link: CVE-2023-5601

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-06T21:15:10.063

Modified: 2023-11-14T19:03:39.863


Link: CVE-2023-5601

JSON object: View

cve-icon Redhat Information

No data.

CWE