Local File Inclusion in Dropbox Folder Share for WordPress by HynoTech
CVE-2023-4488
What is CVE-2023-4488?
The Dropbox Folder Share extension for WordPress is susceptible to a Local File Inclusion vulnerability due to improper handling of the editor-view.php file. This flaw allows unauthenticated attackers to manipulate file inclusion, thus executing arbitrary PHP code on the server. By exploiting this vulnerability, attackers can bypass access controls, access sensitive information, and potentially execute malicious payloads by uploading files that could be misinterpreted as safe, such as images. The vulnerability specifically affects versions up to and including 1.9.7, putting many WordPress sites at risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Dropbox Folder Share * <= 1.9.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved