NA

CVE-2023-5601

Published: 06/11/2023 Updated: 14/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The WooCommerce Ninja Forms Product Add-ons WordPress plugin prior to 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.

Vulnerable Product Search on Vulmon Subscribe to Product

atomicwebstrategy woocommerce ninja forms product add-ons

Github Repositories

CVE-2023-5601 (WooCommerce Ninja Forms Product Add-ons <= 170 - Unauthenticated Arbitrary File Upload) (RCE) CVE-2023-5601 Poc & Exploit For Sell!! Contact : tme/codeb0ss to buy Ref: wwwwordfencecom/threat-intel/vulnerabilities/wordpress-plugins/woocommerce-ninjaforms-product-addons/woocommerce-ninja-forms-product-add-ons-170-unauthenticated-arbitrar