CVE-2023-6091: WordPress Theme Editor plugin <= 2.7.1 - Arbitrary File Upload vulnerability
Published Mar 26, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in mndpsingh287 Theme Editor.This issue affects Theme Editor: from n/a through 2.7.1.
Affected Software
1 affected component
Mndpsingh287 Theme Editor<=2.7.1
Remediation
Information
Update to 2.8 or a higher version.
Event History
Mar 26, 2024
CVE Published
via MITRE·07:49 PM
Data Sourced
via MITRE·07:49 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-6091?
CVE-2023-6091 has a high severity rating due to its potential to allow unrestricted file uploads of dangerous types.
2
How do I fix CVE-2023-6091?
To fix CVE-2023-6091, upgrade the mndpsingh287 Theme Editor to version 2.7.2 or later.
3
What is the impact of CVE-2023-6091?
The impact of CVE-2023-6091 can lead to unauthorized access, file manipulation, or server compromise through malicious file uploads.
4
Which versions are affected by CVE-2023-6091?
CVE-2023-6091 affects all versions of Theme Editor from n/a up to and including version 2.7.1.
5
Who is the vendor associated with CVE-2023-6091?
The vendor associated with CVE-2023-6091 is mndpsingh287, who developed the Theme Editor plugin.