First published: Mon Sep 25 2023(Updated: )
The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
MiniOrange Prevent Files / Folders Access | <2.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Prevent files / folders access WordPress plugin is CVE-2023-4238.
The severity of CVE-2023-4238 is high.
The affected software for CVE-2023-4238 is the Prevent files / folders access WordPress plugin version up to 2.5.2.
CVE-2023-4238 is a vulnerability in the Prevent files / folders access WordPress plugin that allows attackers to upload arbitrary files on the server.
To fix CVE-2023-4238, update the Prevent files / folders access WordPress plugin to version 2.5.2 or higher.