Security Advisory

CVE-2023-5931

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-12-26 18:33:01
Last updated 2024-08-02 08:14:25
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.6.16 does not validate files to be uploaded, which could allow attackers with a low-privilege account (e.g. subscribers) to upload arbitrary files such as PHP on the server