Arbitrary file reading vulnerability in Code Explorer WordPress plugin
CVE-2023-5816
4.9MEDIUM
Key Information
- Vendor
- Qriouslad
- Status
- Code Explorer
- Vendor
- CVE Published:
- 30 October 2024
Summary
The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and including, 1.4.5. This is due to the fact that the plugin does not restrict accessing files to those outside of the WordPress instance, though the intention of the plugin is to only access WordPress related files. This makes it possible for authenticated attackers, with administrator-level access, to read files outside of the WordPress instance.
Affected Version(s)
Code Explorer <= 1.4.5
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published.
Disclosed
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database
Credit
Dmitrii Ignatyev