PT-2024-14887 · WordPress · Essential Real Estate

Krzysztof Zając

+1

·

Published

2024-01-08

·

Updated

2024-09-04

·

CVE-2023-6140

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Essential Real Estate WordPress plugin versions prior to 4.4.0
Description The issue allows users with limited privileges, such as subscribers, to upload malicious PHP files disguised as ZIP archives, potentially leading to remote code execution.
Recommendations For versions prior to 4.4.0, update to version 4.4.0 or later to resolve the issue. As a temporary workaround, consider restricting file upload capabilities for users with limited privileges until the update can be applied.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2023-6140

Affected Products

Essential Real Estate