CVE-2023-2996
Summary
| CVE | CVE-2023-2996 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-27 14:15:00 UTC |
| Updated | 2023-11-07 04:13:00 UTC |
| Description | The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Automattic |
Jetpack |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| Jetpack < 12.1.1 - Author+ Arbitrary File Manipulation via API WordPress Security Vulnerability |
MISC |
wpscan.com |
|
| Jetpack 12.1.1: Critical Security Update |
MISC |
jetpack.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.