CVE-2023-5762: Filr – Secure document library < 1.2.3.6 - Author+ RCE via file upload with phar ext
The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows the operating system to execute commands and fully compromise the server on behalf of a user with Author-level privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-5762?
CVE-2023-5762 is a Remote Code Execution (RCE) vulnerability in the Filr WordPress plugin version before 1.2.3.6.
What is the severity of CVE-2023-5762?
CVE-2023-5762 has a severity rating of 8.8, which is considered high.
How can the Filr WordPress plugin be affected by CVE-2023-5762?
The Filr WordPress plugin version before 1.2.3.6 is susceptible to CVE-2023-5762, which can lead to remote code execution.
How can an attacker exploit CVE-2023-5762?
An attacker can exploit CVE-2023-5762 by uploading a malicious file with the .phar extension, which allows them to execute commands and compromise the server.
Is there a fix or patch available for CVE-2023-5762?
At the moment, there is no specific fix or patch available for CVE-2023-5762. It is recommended to update to the latest version of the Filr WordPress plugin when it becomes available.