CVE-2023-2688

CWE-22Path Traversal4 documents4 sources
Severity
4.9MEDIUM
EPSS
0.2%
top 58.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateApr 10

Description

The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level attackers to move files uploaded with the plugin (located in wp-content/uploads by default) outside of the web root.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages4 packages

Patches

🔴Vulnerability Details

3
VulDB
File Upload Plugin/File Upload Pro Plugin up to 4.19.1 on WordPress path traversal2026-04-10
GHSA
GHSA-9f3m-9cwg-r3h9: The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 42023-06-09
CVEList
WordPress File Upload / WordPress File Upload Pro <= 4.19.1 - Authenticated (Administrator+) Path Traversal2023-06-09