7.2
CVE-2023-5939
- EPSS 1.33%
- Veröffentlicht 26.12.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:42:49
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
rtMedia for WordPress, BuddyPress and bbPress < 4.6.16 - Admin+ RCE
rtMedia for WordPress, BuddyPress and bbPress WordPress <= 4.6.15 - Authenticated (Admin+) Arbitrary File Upload
The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 loads the contents of the import file in an unsafe manner, leading to remote code execution by privileged users.
Mögliche Gegenmaßnahme
rtMedia for WordPress, BuddyPress and bbPress: Update to version 4.6.16, or a newer patched version
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.33% | 0.674 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
https://wpscan.com/vulnerability/db5d41fc-bcd3-414f-aa99-54d5537007bc
https://www.wordfence.com/threat-intel/vulnerabilities/id/d619d300-8bba-45a1-bd0a-d82e9066a43d