CVE-2023-5414

CRITICAL

Icegram Express <= 5.6.23 - Authenticated Path Traversal via show_es_logs Function

Title source: llm
STIX 2.1

Description

The Icegram Express plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 5.6.23 via the show_es_logs function. This allows administrator-level attackers to read the contents of arbitrary files on the server, which can contain sensitive information including those belonging to other sites, for example in shared hosting environments.

Scores

CVSS v3 9.1
EPSS 0.0103
EPSS Percentile 59.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
icegram/Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress < 5.6.23
icegram/icegram_express < 5.6.23
Published Oct 20, 2023
Tracked Since Feb 18, 2026