The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Dec 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-12-05T16:48:09.882Z
Reserved: 2023-05-30T19:10:08.911Z
Link: CVE-2023-2996

Updated: 2024-08-02T06:41:03.950Z

Status : Modified
Published: 2023-06-27T14:15:11.723
Modified: 2024-11-21T07:59:43.287
Link: CVE-2023-2996

No data.