CVE-2023-6636: Greenshift – animation and page builder blocks <= 7.6.2 - Authenticated (Administrator+) Arbitrary File Upload
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the 'gspbsavefiles' function in versions up to, and including, 7.6.2. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6636?
CVE-2023-6636 is rated as a high severity vulnerability due to its potential for arbitrary file uploads.
How do I fix CVE-2023-6636?
To fix CVE-2023-6636, update the Greenshift plugin to version 7.6.3 or later.
Who is affected by CVE-2023-6636?
Authenticated users with administrator-level privileges on versions of the Greenshift plugin up to 7.6.2 are affected by CVE-2023-6636.
What type of vulnerability is CVE-2023-6636?
CVE-2023-6636 is an arbitrary file upload vulnerability resulting from inadequate file type validation.
Can CVE-2023-6636 be exploited remotely?
CVE-2023-6636 requires authenticated access, meaning it cannot be exploited remotely without valid login credentials.