Vulnerability Description
The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kiwiz Invoices Certification \& Pdf System Project | Kiwiz Invoices Certification \& Pdf System | <= 2.1.3 |
References
- https://wpscan.com/vulnerability/4d3b90d8-8a6d-4b72-8bc7-21f861259a1bExploit
- https://wpscan.com/vulnerability/4d3b90d8-8a6d-4b72-8bc7-21f861259a1bExploit
FAQ
What is CVE-2023-2180?
CVE-2023-2180 is a vulnerability with a CVSS score of 7.5 (HIGH). The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary...
How severe is CVE-2023-2180?
CVE-2023-2180 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2180?
Check the references section above for vendor advisories and patch information. Affected products include: Kiwiz Invoices Certification \& Pdf System Project Kiwiz Invoices Certification \& Pdf System.