Lucene search

K
nvd[email protected]NVD:CVE-2023-4019
HistorySep 04, 2023 - 12:15 p.m.

CVE-2023-4019

2023-09-0412:15:10
web.nvd.nist.gov
3
cve-2023-4019
wordpress plugin
unauthorized file movement
rce

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

37.1%

The Media from FTP WordPress plugin before 11.17 does not properly limit who can use the plugin, which may allow users with author+ privileges to move files around, like wp-config.php, which may lead to RCE in some cases.

Affected configurations

Nvd
Node
riverforest-wpmedia_from_ftpRange<11.17wordpress
VendorProductVersionCPE
riverforest-wpmedia_from_ftp*cpe:2.3:a:riverforest-wp:media_from_ftp:*:*:*:*:*:wordpress:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.6

Confidence

High

EPSS

0.001

Percentile

37.1%