CVE-2023-6826

The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'import_action' function in versions up to, and including, 1.20.25. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Configurations

Configuration 1 (hide)

cpe:2.3:a:e2pdf:e2pdf:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2023-12-15 08:15

Updated : 2023-12-21 04:49


NVD link : CVE-2023-6826

Mitre link : CVE-2023-6826

CVE.ORG link : CVE-2023-6826


JSON object : View

Products Affected

e2pdf

  • e2pdf
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type