PoC Index

CVE-2023-6140

HIGH 8.8EPSS 1.1%

The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files disguised as ZIP archives, which may lead to remote code execution.

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.09% chance of exploitation in the next 30 days, 63th percentile
Published
2024-01-08
Updated
2024-09-04

Proof-of-concept exploits (1)

References

Related