CVE-2023-6827
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Dec 15, 2023
Updated: Dec 21, 2023
CWE ID 434
Summary
CVE-2023-6827: The Essential Real Estate plugin for WordPress, versions up to 4.3.5, is susceptible to arbitrary file uploads. The vulnerability lies within the 'ajaxUploadFonts' function, where insufficient file type validation occurs. Authenticated attackers, including those with subscriber- level access, can exploit this weakness to upload arbitrary files, potentially leading to remote code execution on the affected server.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share