PT-2023-17545 · WordPress · Advanced File Manager Shortcodes
Mateus Machado Tesser
·
Published
2023-06-27
·
Updated
2026-03-10
·
CVE-2023-2068
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
File Manager Advanced Shortcode WordPress plugin versions 2.3.2 and earlier
Description
The issue arises from inadequate prevention of uploading files with disallowed MIME types when using the shortcode, leading to remote code execution (RCE) in cases where the allowed MIME type list does not include PHP files. This can be exploited by unauthenticated users in the worst-case scenario.
Recommendations
For versions 2.3.2 and earlier, update to a version that includes a fix for this issue to prevent the uploading of files with disallowed MIME types.
As a temporary workaround, consider restricting access to the shortcode or disabling it until a patch is available.
Restrict the allowed MIME type list to only include necessary file types to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Advanced File Manager Shortcodes