Local File Inclusion in Dropbox Folder Share for WordPress by HynoTech
CVE-2023-4488
9.8CRITICAL
Summary
The Dropbox Folder Share extension for WordPress is susceptible to a Local File Inclusion vulnerability due to improper handling of the editor-view.php file. This flaw allows unauthenticated attackers to manipulate file inclusion, thus executing arbitrary PHP code on the server. By exploiting this vulnerability, attackers can bypass access controls, access sensitive information, and potentially execute malicious payloads by uploading files that could be misinterpreted as safe, such as images. The vulnerability specifically affects versions up to and including 1.9.7, putting many WordPress sites at risk.
Affected Version(s)
Dropbox Folder Share * <= 1.9.7
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Marco Wotschka