PoC Index

CVE-2023-2068

CRITICAL 9.8EPSS 39.6%

The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
39.62% chance of exploitation in the next 30 days, 99th percentile
Published
2023-06-27
Updated
2025-02-13

Proof-of-concept exploits (2)

Metasploit modules (1)

ExploitDB entries (1)

References

Related