WordPress Verge3D Plugin <= 4.5.2 is vulnerable to Arbitrary File Upload
CVE-2023-51421
9.9CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 December 2023
What is CVE-2023-51421?
The Verge3D Publishing and E-Commerce by Soft8Soft LLC is affected by an unauthorized file upload vulnerability. This flaw allows attackers to upload files of dangerous types without proper validation, potentially compromising the security of the web application. Users are encouraged to update their installations to the latest version to mitigate this risk.
Affected Version(s)
Verge3D Publishing and E-Commerce <= 4.5.2