CVE-2023-5360
critical · 9.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.
9.8
CVSS
81.7%
EPSS (exploit prob.)
100th
EPSS percentile
2023-10-31
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-434
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| royal-elementor-addons | royal_elementor_addons | < 1.3.79 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/175992/WordPress-Royal-Elementor-Addons-And-Templates-Remote-Shell-Upload.html
- https://wpscan.com/vulnerability/281518ff-7816-4007-b712-63aed7828b34
- http://packetstormsecurity.com/files/175992/WordPress-Royal-Elementor-Addons-And-Templates-Remote-Shell-Upload.html
- https://wpscan.com/vulnerability/281518ff-7816-4007-b712-63aed7828b34
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-5360