Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-2996


The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization.


Published

2023-06-27T14:15:11.723

Last Modified

2024-11-21T07:59:43.287

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses

-


Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application automattic jetpack < 12.1.1 Yes

References