nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-31090 CVE-2023-31090
CRITICAL
WordPress Unlimited Elements For Elementor plugin <= 1.5.60 - Unrestricted Zip Extraction vulnerability
Record summary
CVE-2023-31090 has a selected CVSS score of 9.9 (critical).
Description
Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.60.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Unlimited Elements For Elementor (Free Widgets, Addons, Templates)Browse Unlimited Elements / Unlimited Elements For Elementor (Free Widgets, Addons, Templates)unlimited-elements-for-elementorDefault status: unaffected | CVE List | Through 1.5.60 | affected |
unlimited_elements_for_elementor_\(free_widgets\,_addons\,_templates\)Browse unlimited-elements / unlimited_elements_for_elementor_\(free_widgets\,_addons\,_templates\)Default status: unaffected | CVE List | Through 1.5.60 | affected |
References
2patchstack.comvdb entry
https://patchstack.com/database/vulnerability/unlimited-elements-for-elementor/wordpress-unlimited-elements-for-elementor-plugin-1-5-60-unrestricted-zip-extraction-vulnerability?_s_id=cve