logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-2996

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-2996

Description:
The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization.
Last updated date:
07/03/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
07/03/2023
Reference url to background

https://wpscan.com/vulnerability/52d221bd-ae42-435d-a90a-60a5ae530663

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy