First published: Wed Apr 24 2024(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.60.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Unlimited Elements For Elementor | <1.5.61 | |
Unlimited Elements for Elementor | >n/a<=1.5.60 | |
WordPress Unlimited Elements For Elementor | <=1.5.60 |
Update to 1.5.61 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31090 is classified as a high severity vulnerability due to its potential to allow unauthorized file uploads.
To fix CVE-2023-31090, update the Unlimited Elements For Elementor plugin to version 1.5.61 or later.
CVE-2023-31090 allows the upload of files with dangerous types, including web shells, which can compromise the server.
CVE-2023-31090 affects versions of Unlimited Elements For Elementor prior to 1.5.61, including 1.5.60 and earlier.
If you cannot update, it is recommended to remove the plugin immediately to mitigate the risk associated with CVE-2023-31090.