8.8
CVSSv3

CVE-2023-6140

Published: 08/01/2024 Updated: 11/01/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Essential Real Estate WordPress plugin prior to 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files disguised as ZIP archives, which may lead to remote code execution.

Vulnerable Product Search on Vulmon Subscribe to Product

g5plus essential real estate