CVE-2023-5360
Summary
| CVE | CVE-2023-5360 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-31 14:15:00 UTC |
| Updated | 2023-11-08 18:41:00 UTC |
| Description | The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Royal Elementor Addons and Templates < 1.3.79 – Unauthenticated Arbitrary File Upload | Plugin Vulnerabilities |
MISC |
wpscan.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150736 WordPress Royal Elementor Addons Plugin: Unauthenticated Arbitrary File Upload Vulnerability (CVE-2023-5360)