Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-2996
HistoryJun 27, 2023 - 2:15 p.m.

Deserialization of untrusted data

2023-06-2714:15:00
PRIOn knowledge base
www.prio-n.com
6
jetpack plugin
wordpress
file validation
author role
remote code execution
phar deserialization

8.9 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.8%

The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization.

CPENameOperatorVersion
jetpacklt12.1.1

8.9 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

70.8%