Vulnerability Details CVE-2023-4243
The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install-plugin REST route in versions up to, and including, 2.2.3 due to improper authorization. This allows authenticated attackers with subscriber-level permissions and above to execute code by installing plugins from arbitrary remote locations including non-repository sources onto the site, granted they are packaged as a valid WordPress plugin.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 66.1%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2023-4243
-
cpe:2.3:a:full:full_-_customer:-
-
cpe:2.3:a:full:full_-_customer:0.0.10
-
cpe:2.3:a:full:full_-_customer:0.0.2
-
cpe:2.3:a:full:full_-_customer:0.0.3
-
cpe:2.3:a:full:full_-_customer:0.0.4
-
cpe:2.3:a:full:full_-_customer:0.0.5
-
cpe:2.3:a:full:full_-_customer:0.0.6
-
cpe:2.3:a:full:full_-_customer:0.0.7
-
cpe:2.3:a:full:full_-_customer:0.0.8
-
cpe:2.3:a:full:full_-_customer:0.0.9
-
cpe:2.3:a:full:full_-_customer:0.1.0
-
cpe:2.3:a:full:full_-_customer:0.1.1
-
cpe:2.3:a:full:full_-_customer:0.1.2
-
cpe:2.3:a:full:full_-_customer:0.2.0
-
cpe:2.3:a:full:full_-_customer:0.2.1
-
cpe:2.3:a:full:full_-_customer:0.2.2
-
cpe:2.3:a:full:full_-_customer:0.2.3
-
cpe:2.3:a:full:full_-_customer:0.2.4
-
cpe:2.3:a:full:full_-_customer:1.0.0
-
cpe:2.3:a:full:full_-_customer:1.0.1
-
cpe:2.3:a:full:full_-_customer:1.0.2
-
cpe:2.3:a:full:full_-_customer:1.0.3
-
cpe:2.3:a:full:full_-_customer:1.0.4
-
cpe:2.3:a:full:full_-_customer:1.0.5
-
cpe:2.3:a:full:full_-_customer:1.0.6
-
cpe:2.3:a:full:full_-_customer:1.0.7
-
cpe:2.3:a:full:full_-_customer:1.0.8
-
cpe:2.3:a:full:full_-_customer:1.1.0
-
cpe:2.3:a:full:full_-_customer:1.2
-
cpe:2.3:a:full:full_-_customer:1.2.1
-
cpe:2.3:a:full:full_-_customer:1.2.2
-
cpe:2.3:a:full:full_-_customer:2.0
-
cpe:2.3:a:full:full_-_customer:2.0.1
-
cpe:2.3:a:full:full_-_customer:2.0.2
-
cpe:2.3:a:full:full_-_customer:2.0.3
-
cpe:2.3:a:full:full_-_customer:2.0.4
-
cpe:2.3:a:full:full_-_customer:2.0.5
-
cpe:2.3:a:full:full_-_customer:2.0.6
-
cpe:2.3:a:full:full_-_customer:2.0.7
-
cpe:2.3:a:full:full_-_customer:2.0.8
-
cpe:2.3:a:full:full_-_customer:2.0.9
-
cpe:2.3:a:full:full_-_customer:2.0.9.1
-
cpe:2.3:a:full:full_-_customer:2.1.0
-
cpe:2.3:a:full:full_-_customer:2.1.1
-
cpe:2.3:a:full:full_-_customer:2.1.2
-
cpe:2.3:a:full:full_-_customer:2.2
-
cpe:2.3:a:full:full_-_customer:2.2.1
-
cpe:2.3:a:full:full_-_customer:2.2.2
-
cpe:2.3:a:full:full_-_customer:2.2.3