CVE-2023-39163: WordPress Phlox Shop plugin <= 2.0.0 - Unauthenticated Local File Inclusion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Averta Phlox Shop allows PHP Local File Inclusion.This issue affects Phlox Shop: from n/a through 2.0.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-39163?
CVE-2023-39163 is categorized as a high severity vulnerability due to its potential for PHP Local File Inclusion leading to unauthorized access to sensitive files.
How do I fix CVE-2023-39163?
To fix CVE-2023-39163, update to Phlox Shop version 2.0.1 or higher, which addresses the path traversal issue.
What are the affected versions of CVE-2023-39163?
CVE-2023-39163 affects Averta Phlox Shop versions up to and including 2.0.0.
What type of vulnerability is CVE-2023-39163?
CVE-2023-39163 is a Path Traversal vulnerability that allows improper limitation of a pathname to a restricted directory.
Who is the vendor associated with CVE-2023-39163?
The vendor associated with CVE-2023-39163 is Averta, which develops the Phlox Shop plugin.