CVE-2019-11223: Malicious File Upload
Published Apr 18, 2019
·Updated
An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
Affected Software
1 affected component
SupportCandy SupportCandy WordPress<=2.0.0
Event History
Apr 18, 2019
CVE Published
via MITRE·05:08 PM
Data Sourced
via MITRE·05:08 PM
Description
Frequently Asked Questions
1
What is CVE-2019-11223?
CVE-2019-11223 is an Unrestricted File Upload Vulnerability in the SupportCandy plugin for WordPress.
2
How does CVE-2019-11223 work?
CVE-2019-11223 allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
3
What is the severity of CVE-2019-11223?
CVE-2019-11223 has a severity of critical with a CVSS score of 9.8.
4
Which version of the SupportCandy plugin is affected by CVE-2019-11223?
SupportCandy plugin through version 2.0.0 for WordPress is affected by CVE-2019-11223.
5
How can I mitigate the vulnerability?
To mitigate CVE-2019-11223, update the SupportCandy plugin to a version higher than 2.0.0 or remove the plugin if it is not essential.