WordPress Multiple Plugins Arbitrary File Upload (CVE-2021-39352; CVE-2022-3416; CVE-2022-3912; CVE-2022-3982; CVE-2022-3989; CVE-2022-4047; CVE-2022-4061; CVE-2023-2068; CVE-2023-4596)

Check Point Reference: CPAI-2022-1142 Date Published: 29 Jan 2023 Severity: Critical Last Updated: Wednesday 29 November, 2023 Source: Industry Reference:CVE-2021-39352
CVE-2022-3416
CVE-2022-3912
CVE-2022-3982
CVE-2022-3989
CVE-2022-4047
CVE-2022-4061
CVE-2023-2068
CVE-2023-4596
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? WordPress WPtouch plugin before version 4.3.45
WordPress Motors plugin before 1.4.4
WordPress Forminator plugin prior to 1.24.6
WordPress Catch Themes Demo Import plugin up to and including 1.7 Vulnerability Description An arbitrary file upload vulnerability exists in multiple WordPress plugins. Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the vulnerable system.