Vulnerability Description
The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged user to upload arbitrary files to the web server, triggering an RCE vulnerability by uploading a web shell.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Naziinfotech | Ni Purchase Order\(Po\) For Woocommerce | <= 1.2.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/70f823ff-64ad-4f05-9eb3-b69b3b79dc12ExploitThird Party Advisory
- https://wpscan.com/vulnerability/70f823ff-64ad-4f05-9eb3-b69b3b79dc12ExploitThird Party Advisory
FAQ
What is CVE-2023-5957?
CVE-2023-5957 is a vulnerability with a CVSS score of 7.2 (HIGH). The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged user to upload arbitrary fi...
How severe is CVE-2023-5957?
CVE-2023-5957 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-5957?
Check the references section above for vendor advisories and patch information. Affected products include: Naziinfotech Ni Purchase Order\(Po\) For Woocommerce.