First published: Mon Jun 19 2023(Updated: )
The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Slider Revolution | <=6.6.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-2359 is high with a severity value of 8.8.
CVE-2023-2359 is a vulnerability in the Slider Revolution WordPress plugin that allows for arbitrary file upload and potential remote code execution.
CVE-2023-2359 affects Slider Revolution versions up to 6.6.12 and allows for the upload of invalid image files that can be used to escalate to remote code execution in certain server configurations.
To fix the CVE-2023-2359 vulnerability, you should update Slider Revolution plugin to version 6.6.13 or higher, provided by Themepunch.
You can find more information about CVE-2023-2359 at the following reference: [https://wpscan.com/vulnerability/a8350890-e6d4-4b04-a158-2b0ee3748e65](https://wpscan.com/vulnerability/a8350890-e6d4-4b04-a158-2b0ee3748e65)