The Jetpack WordPress plugin before 12.1.1 does not validate uploaded files, allowing users with author roles or above to manipulate existing files on the site, deleting arbitrary files, and in rare cases achieve Remote Code Execution via phar deserialization.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published: 2023-06-27T13:17:07.479Z
Updated: 2024-12-05T16:48:09.882Z
Reserved: 2023-05-30T19:10:08.911Z
Link: CVE-2023-2996
Updated: 2024-08-02T06:41:03.950Z
Status : Modified
Published: 2023-06-27T14:15:11.723
Modified: 2024-11-21T07:59:43.287
Link: CVE-2023-2996
No data.