CVE-2023-5957

HIGH

Ni Purchase Order(PO) For WooCommerce < 1.2.1 - Authenticated Arbitrary File Upload via Logo/Signature Settings

Title source: llm
STIX 2.1

Description

The Ni Purchase Order(PO) For WooCommerce WordPress plugin through 1.2.1 does not validate logo and signature image files uploaded in the settings, allowing high privileged user to upload arbitrary files to the web server, triggering an RCE vulnerability by uploading a web shell.

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/70f823ff-64ad-4f05-9eb3-b69b3b79dc12

Scores

CVSS v3 7.2
EPSS 0.0088
EPSS Percentile 54.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
naziinfotech/ni_purchase_order\(po\)_for_woocommerce < 1.2.1
Published Jan 08, 2024
Tracked Since Feb 18, 2026