CVE-2023-34007: WordPress Download Monitor Plugin <= 4.8.3 is vulnerable to Arbitrary File Upload
Published Dec 20, 2023
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3.
Affected Software
1 affected component
WPChill Download Monitor Wordpress<=4.8.3
Remediation
Information
Update to 4.8.4 or a higher version.
Event History
Dec 20, 2023
CVE Published
via MITRE·06:49 PM
Data Sourced
via MITRE·06:49 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-34007?
CVE-2023-34007 is categorized as a high severity vulnerability due to its potential for unrestricted file uploads.
2
How do I fix CVE-2023-34007?
To fix CVE-2023-34007, update the Download Monitor plugin to a version above 4.8.3.
3
Which versions of Download Monitor are affected by CVE-2023-34007?
CVE-2023-34007 affects Download Monitor versions up to and including 4.8.3.
4
What is the impact of exploiting CVE-2023-34007?
Exploiting CVE-2023-34007 allows attackers to upload potentially harmful files to the server.
5
Is there a workaround for CVE-2023-34007 if I cannot update?
If an update is not possible, disabling the file upload feature in the Download Monitor settings may serve as a temporary workaround.