CVE-2023-5601 Information

Description

The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded allowing any unauthenticated users to upload arbitrary files to the server leading to RCE.

Reference

https://wpscan.com/vulnerability/0035ec5e-d405-4eb7-8fe4-29dd0c71e4bc

Share on: