CVE-2023-6635: EditorsKit <= 1.40.3 - Authenticated (Administrator+) Arbitrary File Upload
The EditorsKit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the 'importstyles' function in versions up to, and including, 1.40.3. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6635?
CVE-2023-6635 is a critical vulnerability that allows authenticated attackers to upload arbitrary files.
How do I fix CVE-2023-6635?
To fix CVE-2023-6635, update the EditorsKit plugin to version 1.40.4 or later.
Who is affected by CVE-2023-6635?
CVE-2023-6635 affects users of the EditorsKit plugin for WordPress versions up to 1.40.3.
What conditions are required for CVE-2023-6635 to be exploited?
CVE-2023-6635 can be exploited by authenticated users with administrator-level capabilities.
What does CVE-2023-6635 allow an attacker to do?
CVE-2023-6635 allows an attacker to upload arbitrary files to the WordPress site, potentially leading to remote code execution.