CVE-2023-2288: Otter - Gutenberg Blocks < 2.2.6 - Author+ PHAR Deserialization
Published May 30, 2023
·Updated
The Otter WordPress plugin before 2.2.6 does not sanitize some user-controlled file paths before performing file operations on them. This leads to a PHAR deserialization vulnerability on PHP < 8.0 using the phar:// stream wrapper.
Affected Software
1 affected component
Themeisle Otter Wordpress<2.2.6
Event History
May 30, 2023
CVE Published
via MITRE·07:49 AM
Data Sourced
via MITRE·07:49 AM
DescriptionWeakness
Data Sourced
08:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of the Otter WordPress plugin issue?
The vulnerability ID is CVE-2023-2288.
2
What is the severity level of CVE-2023-2288?
The severity level of CVE-2023-2288 is high.
3
What is the description of CVE-2023-2288?
CVE-2023-2288 is a PHAR deserialization vulnerability in the Otter WordPress plugin before version 2.2.6, which allows remote attackers to execute arbitrary code.
4
How does CVE-2023-2288 impact PHP versions below 8.0?
CVE-2023-2288 leads to a PHAR deserialization vulnerability on PHP versions below 8.0 using the phar:// stream wrapper.
5
Is there a fix available for CVE-2023-2288?
Yes, upgrading to version 2.2.6 of the Otter WordPress plugin addresses the vulnerability CVE-2023-2288.