Local File Inclusion Vulnerability in HTML Filter and CSV Search Plugin for WordPress
CVE-2023-5099
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 October 2023
What is CVE-2023-5099?
The HTML filter and CSV file search plugin for WordPress is susceptible to a Local File Inclusion flaw that affects versions up to and including 2.7. This vulnerability originates from the 'src' attribute in the 'csvsearch' shortcode, enabling authenticated users with contributor-level permissions or higher to potentially include and execute arbitrary files hosted on the server. Attackers can exploit this flaw to bypass access controls, access sensitive data, or execute arbitrary PHP code, posing significant security risks even when uploading seemingly safe file types like images.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HTML filter and csv-file search * <= 2.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved