CVE-2023-1406: JetEngine < 3.1.3.1 - Author+ Remote Code Execution
Published Apr 10, 2023
·Updated
The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability.
Affected Software
1 affected component
Crocoblock Jetengine For Elementor Wordpress<3.1.3.1
Event History
Apr 10, 2023
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-1406?
CVE-2023-1406 is rated as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2023-1406?
To fix CVE-2023-1406, update the JetEngine plugin to version 3.1.3.1 or later.
3
What is the impact of CVE-2023-1406?
CVE-2023-1406 allows attackers to execute arbitrary code on affected WordPress sites by exploiting file upload features.
4
Which versions are affected by CVE-2023-1406?
CVE-2023-1406 affects JetEngine WordPress plugin versions prior to 3.1.3.1.
5
Is CVE-2023-1406 related to any specific feature of JetEngine?
Yes, CVE-2023-1406 is related to the plugin's handling of uploaded files without proper validation to prevent execution.