PT-2024-14835 · WordPress · Code Explorer

Dmitry Ignatyev

·

Published

2024-10-30

·

Updated

2024-11-07

·

CVE-2023-5816

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Code Explorer plugin for WordPress versions up to, and including, 1.4.5
Description The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading due to the lack of restriction on accessing files outside of the WordPress instance. This allows authenticated attackers with administrator-level access to read files outside of the WordPress instance.
Recommendations For versions up to, and including, 1.4.5, update to the latest version available to protect your site from this vulnerability. As a temporary workaround, consider restricting access to sensitive files and directories until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-5816

Affected Products

Code Explorer