PT-2023-17545 · WordPress · Advanced File Manager Shortcodes

Mateus Machado Tesser

·

Published

2023-06-27

·

Updated

2026-03-10

·

CVE-2023-2068

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions File Manager Advanced Shortcode WordPress plugin versions 2.3.2 and earlier
Description The issue arises from inadequate prevention of uploading files with disallowed MIME types when using the shortcode, leading to remote code execution (RCE) in cases where the allowed MIME type list does not include PHP files. This can be exploited by unauthenticated users in the worst-case scenario.
Recommendations For versions 2.3.2 and earlier, update to a version that includes a fix for this issue to prevent the uploading of files with disallowed MIME types. As a temporary workaround, consider restricting access to the shortcode or disabling it until a patch is available. Restrict the allowed MIME type list to only include necessary file types to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-2068

Affected Products

Advanced File Manager Shortcodes