The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files disguised as ZIP archives, which may lead to remote code execution.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-09-04T15:36:41.937Z
Reserved: 2023-11-14T22:50:43.564Z
Link: CVE-2023-6140

Updated: 2024-08-02T08:21:17.679Z

Status : Modified
Published: 2024-01-08T19:15:10.027
Modified: 2024-11-21T08:43:13.170
Link: CVE-2023-6140

No data.