CVE-2023-2068 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 39.6% (pctl 99)
Patch early
A public exploit exists.
Description
The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 39.62% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2023-06-27 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| advancedfilemanager | file manager advanced shortcode |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | File Manager Advanced Shortcode 2.3.2 - Unauthenticated Remote Code Execution (RCE) | 2023-06-04 |
References
- http://packetstormsecurity.com/files/173735/WordPress-File-Manager-Advanced-Shortcode-2.3.2-Remote-Code-Execution.html
- https://wpscan.com/vulnerability/58f72953-56d2-4d86-a49b-311b5fc58056
- http://packetstormsecurity.com/files/173735/WordPress-File-Manager-Advanced-Shortcode-2.3.2-Remote-Code-Execution.html
- https://wpscan.com/vulnerability/58f72953-56d2-4d86-a49b-311b5fc58056
→ the Explorer · watch your stack · NVD