The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.
                
            References
                    | Link | Resource | 
|---|---|
| https://wpscan.com/vulnerability/a8350890-e6d4-4b04-a158-2b0ee3748e65 | Exploit Third Party Advisory | 
| https://wpscan.com/vulnerability/a8350890-e6d4-4b04-a158-2b0ee3748e65 | Exploit Third Party Advisory | 
| https://wpscan.com/vulnerability/a8350890-e6d4-4b04-a158-2b0ee3748e65/ | 
Configurations
                    History
                    12 Dec 2024, 17:15
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
 | 
Information
                Published : 2023-06-19 11:15
Updated : 2024-12-12 17:15
NVD link : CVE-2023-2359
Mitre link : CVE-2023-2359
CVE.ORG link : CVE-2023-2359
JSON object : View
Products Affected
                themepunch
- slider_revolution
CWE
                
                    
                        
                        CWE-94
                        
            Improper Control of Generation of Code ('Code Injection')
