FULL - Customer <= 2.2.3 - Authenticated(Subscriber+) Improper Authorization to Arbitrary Plugin Installation
Published Aug 9, 2023
8.8
HIGHCVSS 3.1
EPSS 0.90%
Description
The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and above to execute code by installing plugins from arbitrary remote locations including non-repository sources onto the site, granted they are packaged as a valid WordPress plugin.
Affected products
-
- Version 0StatusaffectedConstraints<=2.2.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Fullservices | FULL – Cliente | unaffected |
|
- ≤ 2.2.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Feb 5, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.90% (0.00900) | 58.28th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.77% (0.00765) | 50.46th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.53% (0.00531) | 66.41th | v4 (v2025.03.14) |
| Nov 18, 2025 | 1.82% (0.01817) | 81.38th | v4 (v2025.03.14) |
| Apr 15, 2025 | 0.53% (0.00525) | 65.69th | v4 (v2025.03.14) |
| Mar 30, 2025 | 1.80% (0.01798) | 81.15th | v4 (v2025.03.14) |
| Mar 29, 2025 | 7.44% (0.07436) | 85.95th | v4 (v2025.03.14) |
| Mar 24, 2025 | 1.80% (0.01798) | 81.12th | v4 (v2025.03.14) |
| Mar 23, 2025 | 3.15% (0.03148) | 84.45th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.34% (0.01339) | 78.67th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.22% (0.00216) | 60.45th | v3 (v2023.03.01) |
| Jul 9, 2024 | 0.09% (0.00090) | 38.71th | v3 (v2023.03.01) |
| Jun 15, 2024 | 0.08% (0.00077) | 33.24th | v3 (v2023.03.01) |
| Aug 15, 2023 | 0.06% (0.00064) | 26.57th | v3 (v2023.03.01) |
| Aug 9, 2023 | 0.06% (0.00057) | 21.59th | v3 (v2023.03.01) |
References (4)
- https://plugins.trac.wordpress.org/browser/full-customer/tags/1.1.0/app/api/Plugin.php Product
- https://plugins.trac.wordpress.org/browser/full-customer/tags/2.2.1/app/api/PluginInstallation.php Product
- https://plugins.trac.wordpress.org/browser/full-customer/tags/2.3/app/api/Controller.php?rev=2951561
- https://www.wordfence.com/threat-intel/vulnerabilities/id/9799df3f-e34e-42a7-8a72-fa57682f7014?source=cve Third Party Advisory
Change history (0)
No recorded changes yet.