The E2Pdf plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'import_action' function in versions up to, and including, 1.20.25. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin, to upload arbitrary files on the affected site's server which may make remote code execution possible.
References
Configurations
Information
Published : 2023-12-15 08:15
Updated : 2023-12-21 04:49
NVD link : CVE-2023-6826
Mitre link : CVE-2023-6826
JSON object : View
Products Affected
e2pdf
- e2pdf
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
