CVE-2023-5601
06.11.2023, 21:15
The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.Enginsight
Vendor | Product | Version |
---|---|---|
atomicwebstrategy | woocommerce_ninja_forms_product_add-ons | 𝑥 < 1.7.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration