CVE-2023-31090: WordPress Unlimited Elements For Elementor plugin <= 1.5.60 - Unrestricted Zip Extraction vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.60.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31090?
CVE-2023-31090 is classified as a high severity vulnerability due to its potential to allow unauthorized file uploads.
How do I fix CVE-2023-31090?
To fix CVE-2023-31090, update the Unlimited Elements For Elementor plugin to version 1.5.61 or later.
What types of files can be uploaded due to CVE-2023-31090?
CVE-2023-31090 allows the upload of files with dangerous types, including web shells, which can compromise the server.
Which versions of Unlimited Elements For Elementor are affected by CVE-2023-31090?
CVE-2023-31090 affects versions of Unlimited Elements For Elementor prior to 1.5.61, including 1.5.60 and earlier.
What should I do if I can't update to fix CVE-2023-31090?
If you cannot update, it is recommended to remove the plugin immediately to mitigate the risk associated with CVE-2023-31090.