{ "schema_version": "1.4.0", "id": "GHSA-6c5h-fjmf-jpg3", "modified": "2024-04-04T04:19:23Z", "published": "2023-05-24T00:30:25Z", "aliases": [ "CVE-2023-2496" ], "details": "The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability check on the 'validate_upload' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin to upload arbitrary files on the affected site's server which may make remote code execution possible.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-2496" }, { "type": "WEB", "url": "https://codecanyon.net/item/go-pricing-wordpress-responsive-pricing-tables/3725820" }, { "type": "WEB", "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/477c6fa2-16a8-4461-b4d4-d087e13e3ca7?source=cve" } ], "database_specific": { "cwe_ids": [ "CWE-285" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-24T00:15:09Z" } }