CVE-2023-5673: WP Mail Log < 1.1.3 – Contributor+ Arbitrary File Upload to RCE
Published Dec 26, 2023
·Updated
The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file extensions uploading files to attach to emails, allowing attackers to upload PHP files, leading to remote code execution.
Affected Software
1 affected component
WPVibes Wp Mail Log Wordpress<1.1.3
Event History
Dec 26, 2023
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
DescriptionWeakness
May 24, 57290
Event
via FIRST·01:24 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-5673?
CVE-2023-5673 is considered to have a critical severity due to the potential for remote code execution.
2
How do I fix CVE-2023-5673?
To fix CVE-2023-5673, update the WP Mail Log plugin to version 1.1.3 or later.
3
What are the potential exploits of CVE-2023-5673?
Attackers can exploit CVE-2023-5673 to upload malicious PHP files, resulting in remote code execution on the server.
4
Which versions of the WP Mail Log plugin are affected by CVE-2023-5673?
CVE-2023-5673 affects all versions of the WP Mail Log plugin prior to version 1.1.3.
5
Is there a workaround for CVE-2023-5673 until I can update?
A possible workaround for CVE-2023-5673 is to disable file uploads in the WP Mail Log plugin settings.