logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2023-5886

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2023-5886

Description:
The Export any WordPress data to XML/CSV WordPress plugin before 1.4.0, WP All Export Pro WordPress plugin before 1.8.6 does not check nonce tokens early enough in the request lifecycle, allowing attackers with the ability to upload files to make logged in users perform unwanted actions leading to PHAR deserialization, which may lead to remote code execution.
Last updated date:
12/21/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
12/21/2023
Reference url to background

https://wpscan.com/vulnerability/0a08e49d-d34e-4140-a15d-ad64444665a3

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy