CVE-2023-5860: Icons Font Loader <= 1.1.2 - Authenticated (Administrator+) Arbitrary File Upload
The Icons Font Loader plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload function in all versions up to, and including, 1.1.2. This makes it possible for authenticated attackers, with administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-5860?
CVE-2023-5860 is a vulnerability in the Icons Font Loader plugin for WordPress that allows authenticated attackers to upload arbitrary files.
What is the severity of CVE-2023-5860?
The severity of CVE-2023-5860 is high with a severity value of 7.2.
How does CVE-2023-5860 work?
CVE-2023-5860 is caused by missing file type validation in the upload function of the Icons Font Loader plugin, allowing authenticated attackers to upload arbitrary files.
Which versions of the Icons Font Loader plugin for WordPress are affected by CVE-2023-5860?
All versions of the Icons Font Loader plugin for WordPress up to and including 1.1.2 are affected by CVE-2023-5860.
Is there a fix available for CVE-2023-5860?
Yes, a fix is available for CVE-2023-5860. Update your Icons Font Loader plugin for WordPress to version 1.1.3 or later to mitigate the vulnerability.