QID 150736
Date Published: 2023-10-23
QID 150736: WordPress Royal Elementor Addons Plugin: Unauthenticated Arbitrary File Upload Vulnerability (CVE-2023-5360)
Royal Elementor addons is the most versatile, intuitive, and easy to use Popular Page Builder extension.
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to arbitrary file uploads. This is due to insufficient file type validation in the handle_file_upload() function called via AJAX which allows attackers to supply a preferred filetype extension to the "allowed_file_types" parameter, with a special character, which makes it possible for the uploaded file to bypass their filter list.
Affected versions:
Royal Elementor addons prior to version 1.3.79
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation of this vulnerability allows unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
- Royal Elementor Addons and Templates -
wordpress.org/plugins/royal-elementor-addons/#developers
CVEs related to QID 150736
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Royal Elementor Addons and Templates |
|