CRITICAL
WordPress MainWP File Uploader Extension Plugin <= 4.1 - Unauthenticated Arbitrary File Upload Vulnerability
Published Mar 26, 2024
10.0
CRITICALCVSS 3.1
EPSS 0.81%
Description
Unrestricted Upload of File with Dangerous Type vulnerability in MainWP MainWP File Uploader Extension.This issue affects MainWP File Uploader Extension: from n/a through 4.1.
Affected products
-
Affected
- ≤ 4.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| MainWP | MainWP File Uploader Extension | unaffected | Affected
|
No data.
-
Affected
- ≥ 0, ≤ 4.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Mainwp | Mainwp File Uploader Extension | unknown | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to 4.1.1 or a higher version.
Weaknesses (1)
References (2)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Patchstack
Published Mar 26, 2024
Updated Apr 28, 2026
Reserved Jan 17, 2023
Link CVE-2023-23656
CISA Vulnrichment
Updated Aug 7, 2024
Red Hat
No data
GitHub
No data