CVE-2023-6140

HIGH

Essential Real Estate <4.4.0 - RCE

Title source: llm
STIX 2.1

Description

The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files disguised as ZIP archives, which may lead to remote code execution.

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/c837eaf3-fafd-45a2-8f5e-03afb28a765b

Scores

CVSS v3 8.8
EPSS 0.0389
EPSS Percentile 88.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
g5plus/essential_real_estate < 4.4.0
Published Jan 08, 2024
Tracked Since Feb 18, 2026