VDB

CVE-2023-5360

CVE-2023-5360 PUBLISHED CVSS 9.800000190734863 CRITICAL

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.

EPSS 81.70% · 99.6th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
81.70%
99.6th percentile

Affected Products

VendorProductVersions
UnknownRoyal Elementor Addons and Templates0, 0
royal-elementor-addonsroyal_elementor_addons0, 0, 0

Timeline

  • CVE Published
  • Jan 20, 1970 VulnCheck XDB Entry
  • Jan 20, 1970 VulnCheck XDB Entry
  • Jan 20, 1970 VulnCheck XDB Entry
  • Jan 20, 1970 VulnCheck XDB Entry
  • Jan 20, 1970 VulnCheck XDB Entry
  • Jan 21, 1970 VulnCheck XDB Entry
  • Jan 21, 1970 VulnCheck XDB Entry
  • Oct 13, 2023 VulnCheck KEV Exploitation
  • Oct 16, 2023 PoC Published
  • Oct 17, 2023 Nuclei Template
  • Oct 17, 2023 Fix Commit
Open in Interactive Console →
$ Console Community · 100/wk Open console ›