Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-6846
HistoryFeb 05, 2024 - 10:15 p.m.

Design/Logic Flaw

2024-02-0522:15:00
PRIOn knowledge base
www.prio-n.com
7
wordpress
file manager pro
arbitrary file upload
vulnerability
code execution
version 8.3.4
version 8.3.5
capability check

7.2 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

23.0%

The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_filemanager_php_syntax AJAX function. This makes it possible for authenticated attackers, with subscriber access and above, to execute code on the server. Version 8.3.5 introduces a capability check that prevents users lower than admin from executing this function.

CPENameOperatorVersion
file_manager_prole8.3.4

7.2 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

23.0%

Related for PRION:CVE-2023-6846