CVE-2023-6979: Customer Reviews for WooCommerce <= 5.38.9 - Authenticated (Author+) Arbitrary File Upload
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ivoleimportuploadcsv AJAX action in all versions up to, and including, 5.38.9. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6979?
CVE-2023-6979 is considered a high severity vulnerability due to the potential for arbitrary file uploads.
How do I fix CVE-2023-6979?
To fix CVE-2023-6979, update the Customer Reviews for WooCommerce plugin to the latest version beyond 5.38.9.
Who is affected by CVE-2023-6979?
Authenticated users with author-level access on WordPress sites using versions of the plugin up to and including 5.38.9 are affected by CVE-2023-6979.
What types of attacks can CVE-2023-6979 facilitate?
CVE-2023-6979 can facilitate attacks that allow unauthorized file uploads, potentially leading to code execution or further exploitation.
What versions of the Customer Reviews for WooCommerce plugin are vulnerable to CVE-2023-6979?
All versions of the Customer Reviews for WooCommerce plugin up to and including 5.38.9 are vulnerable to CVE-2023-6979.