peter bassill · operator
$ cve CVE-2023-2068 JSON

CVE-2023-2068 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 39.6% (pctl 99)

Patch early

A public exploit exists.

Description

The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS39.62% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2023-06-27
Last modified2026-06-17

Affected (1)

VendorProduct
advancedfilemanagerfile manager advanced shortcode

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD