nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-2359 CVE-2023-2359
HIGHRansomware
Revolution Slider <= 6.6.12 - Author+ Remote Code Execution
Record summary
CVE-2023-2359 has a selected CVSS score of 8.8 (high). VulnCheck reports CVE-2023-2359 use in known ransomware campaigns.
Description
The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 19, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
- Ransomware use
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 12, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Slider RevolutionDefault status: affected | CVE List | Through 6.6.12 | affected |
slider_revolutionBrowse themepunch / slider_revolution | VulnCheck | Version data not supplied | |
References
2wpscan.comexploitvdb entryTechnical description
https://wpscan.com/vulnerability/a8350890-e6d4-4b04-a158-2b0ee3748e65