CVE-2023-0080: Customer Reviews for WooCommerce < 5.16.0 - Contributor+ LFI
The Customer Reviews for WooCommerce WordPress plugin before 5.16.0 does not validate one of its shortcode attribute, which could allow users with a contributor role and above to include arbitrary files via a traversal attack. This could also allow them to read non PHP files and retrieve their content. RCE could also be achieved if the attacker manage to upload a malicious image containing PHP code, and then include it via the affected attribute, on a default WP install, authors could easily achieve that given that they have the uploadfile capability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0080?
CVE-2023-0080 has a medium severity rating due to its potential for unauthorized file access.
How do I fix CVE-2023-0080?
To fix CVE-2023-0080, update the Customer Reviews for WooCommerce plugin to version 5.16.0 or later.
Which versions of Customer Reviews for WooCommerce are affected by CVE-2023-0080?
CVE-2023-0080 affects all versions of Customer Reviews for WooCommerce before 5.16.0.
What types of files can be accessed due to CVE-2023-0080?
Due to CVE-2023-0080, users may potentially access non-PHP files on the server.
Who is impacted by CVE-2023-0080?
CVE-2023-0080 impacts users with a contributor role and above in the WordPress site using the affected plugin.