CVE-2023-5957

HIGH

Naziinfotech NI Purchase Order(po) Fo... - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged user to upload arbitrary files to the web server, triggering an RCE vulnerability by uploading a web shell.

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/70f823ff-64ad-4f05-9eb3-b69b3b79dc12

Scores

CVSS v3 7.2
EPSS 0.0056
EPSS Percentile 68.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
naziinfotech/ni_purchase_order\(po\)_for_woocommerce < 1.2.1
Published Jan 08, 2024
Tracked Since Feb 18, 2026