Local File Inclusion Vulnerability in HTML Filter and CSV Search Plugin for WordPress
CVE-2023-5099
8.8HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 31 October 2023
Summary
The HTML filter and CSV file search plugin for WordPress is susceptible to a Local File Inclusion flaw that affects versions up to and including 2.7. This vulnerability originates from the 'src' attribute in the 'csvsearch' shortcode, enabling authenticated users with contributor-level permissions or higher to potentially include and execute arbitrary files hosted on the server. Attackers can exploit this flaw to bypass access controls, access sensitive data, or execute arbitrary PHP code, posing significant security risks even when uploading seemingly safe file types like images.
Affected Version(s)
HTML filter and csv-file search * <= 2.7
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Thomas