8

CVE-2023-48275

Multiple Plugins by Trustindex.io <= (Various Versions)- Authenticated (Editor+) Arbitrary File Upload

Unrestricted Upload of File with Dangerous Type vulnerability in Trustindex.Io Widgets for Google Reviews.This issue affects Widgets for Google Reviews: from n/a through 11.0.2.

Mögliche Gegenmaßnahme
Customer Reviews Collector for WooCommerce: Update to version 4.0, or a newer patched version
Widgets for Reviews & Recommendations: Update to version 11.1, or a newer patched version
Widgets for Airbnb Reviews: Update to version 11.1, or a newer patched version
Widgets for Amazon Reviews: Update to version 11.1, or a newer patched version
Widgets for Árukereső Reviews: Update to version 11.1, or a newer patched version
Widgets for Booking.com Reviews: Update to version 11.1, or a newer patched version
Widgets for Capterra Reviews: Update to version 11.1, or a newer patched version
Widgets for Foursquare Reviews: Update to version 11.1, or a newer patched version
Widgets for Hotels.com Reviews: Update to version 11.1, or a newer patched version
Widgets for Opentable Reviews: Update to version 11.1, or a newer patched version
Review Widgets for Szallas.hu: Update to version 11.1, or a newer patched version
WP Tripadvisor Review Widgets: Update to version 11.1, or a newer patched version
Widgets for WordPress Reviews: Update to version 11.1, or a newer patched version
Widgets for Yelp Reviews: Update to version 11.1, or a newer patched version
Widgets for Alibaba Reviews: Update to version 11.1, or a newer patched version
Widgets for AliExpress Reviews: Update to version 11.1, or a newer patched version
Widgets for Ebay Reviews: Update to version 11.1, or a newer patched version
Widgets for SourceForge Reviews: Update to version 11.1, or a newer patched version
Widgets for Thumbtack Reviews: Update to version 11.1, or a newer patched version
Widgets for Zillow Reviews: Update to version 11.1, or a newer patched version
Widgets for Google Reviews: Update to version 11.1, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Customer Reviews Collector for WooCommerce
Version *-3.9
SystemWordPress Plugin
Produkt Widgets for Reviews & Recommendations
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for Airbnb Reviews
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for Amazon Reviews
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for Árukereső Reviews
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for Booking.com Reviews
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for Capterra Reviews
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for Foursquare Reviews
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for Hotels.com Reviews
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for Opentable Reviews
Version *-11.0.2
SystemWordPress Plugin
Produkt Review Widgets for Szallas.hu
Version *-11.0.2
SystemWordPress Plugin
Produkt WP Tripadvisor Review Widgets
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for WordPress Reviews
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for Yelp Reviews
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for Alibaba Reviews
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for AliExpress Reviews
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for Ebay Reviews
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for SourceForge Reviews
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for Thumbtack Reviews
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for Zillow Reviews
Version *-11.0.2
SystemWordPress Plugin
Produkt Widgets for Google Reviews
Version *-11.0.2
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellertrustindex
Produkt widgets_for_google_reviews
Default Statusunknown
Version <= 11.0.2
Version 0
Status affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.643
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
audit@patchstack.com 8 1.3 6
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.