CVE-2023-46149: WordPress Themify Ultra Theme <= 7.3.5 is vulnerable to Arbitrary File Upload
Published Dec 20, 2023
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5.
Affected Software
1 affected component
Themify Ultra Wordpress<=7.3.5
Remediation
Information
Update to 7.3.6 or a higher version.
Event History
Dec 20, 2023
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-46149?
CVE-2023-46149 has a severity rating that indicates a significant risk due to unrestricted file uploads.
2
How do I fix CVE-2023-46149?
To fix CVE-2023-46149, ensure you update Themify Ultra to version 7.3.6 or later.
3
What software versions are affected by CVE-2023-46149?
CVE-2023-46149 affects all versions of Themify Ultra up to and including version 7.3.5.
4
What kind of attack does CVE-2023-46149 allow?
CVE-2023-46149 allows attackers to upload files of dangerous types, potentially leading to remote code execution.
5
Is there a workaround for CVE-2023-46149?
A potential workaround for CVE-2023-46149 is to disable file uploads until the software is updated.