8.8
CVSSv3

CVE-2023-2249

Published: 09/06/2023 Updated: 07/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request Forgery, and PHAR Deserialization in versions up to, and including, 2.1.7. This is due to the insecure use of file_get_contents without appropriate verification of the data being supplied to the function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to retrieve the contents of files like wp-config.php hosted on the system, perform a deserialization attack and possibly achieve remote code execution, and make requests to internal services.

Vulnerable Product Search on Vulmon Subscribe to Product

gvectors wpforo forum

Github Repositories

Exploit for CVE-2023-2249 in wpForo Forum plugin for WordPress

Original Proof of Concept for CVE-2023-2249 Proof of Concept for vulnerability CVE-2023-2249 in wpForo Forum plugin for WordPress POC Author : githubcom/Ayantaker/ Related Details NVD Link : nvdnistgov/vuln/detail/CVE-2023-2249 Vulnerable versions : version <= 217 Patched version : 218 Vulnerability Analysis CVE-2023-2249: Wordpress Wpforo Plu