PT-2023-29584 · WordPress · Jeff Starr User Submitted Posts

Rafie Muhammad

·

Published

2023-10-16

·

Updated

2023-12-27

·

CVE-2023-45603

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jeff Starr User Submitted Posts – Enable Users to Submit Posts from the Front End versions n/a through 20230902
Description The issue is related to an Unrestricted Upload of File with Dangerous Type, which affects the specified software. This allows for the upload of files with potentially dangerous types, posing a security risk.
Recommendations For versions n/a through 20230902, update to a version later than 20230902 to resolve the issue. As a temporary workaround, consider restricting file uploads to only safe and necessary file types until a patch is available.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-45603

Affected Products

Jeff Starr User Submitted Posts