PT-2023-25829 · WordPress · Upload Media By Url

Dmitriy

·

Published

2023-08-30

·

Updated

2023-09-01

·

CVE-2023-3720

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Upload Media By URL WordPress plugin versions prior to 1.0.8
Description The issue is related to the lack of a CSRF check when uploading files, which could allow attackers to make logged-in admins upload files on their behalf, including HTML containing JS code for users with the unfiltered html capability.
Recommendations For versions prior to 1.0.8, update to version 1.0.8 or later to resolve the issue. As a temporary workaround, consider restricting the unfiltered html capability to minimize the risk of exploitation. Restrict access to file upload functionality to prevent unauthorized uploads until the issue is resolved.

Exploit

Fix

Related Identifiers

CVE-2023-3720

Affected Products

Upload Media By Url