Lucene search

K
vulnrichmentWPScanVULNRICHMENT:CVE-2023-7201
HistoryApr 15, 2024 - 5:00 a.m.

CVE-2023-7201 Everest Backup < 2.2.5 - Admin+ Arbitrary File Upload

2024-04-1505:00:01
WPScan
github.com
1
everest backup
wordpress
plugin
admin
arbitrary files
file upload
security vulnerability

AI Score

6.4

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

The Everest Backup WordPress plugin before 2.2.5 does not properly validate backup files to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:everestthemes:everest_backup:*:*:*:*:*:wordpress:*:*"
    ],
    "vendor": "everestthemes",
    "product": "everest_backup",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "2.2.5",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

AI Score

6.4

Confidence

High

SSVC

Exploitation

poc

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2023-7201